CVE-2007-6610

Publication date 3 January 2008

Last updated 24 July 2024


Ubuntu priority

Description

unp 1.0.12, and other versions before 1.0.14, does not properly escape file names, which might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument. NOTE: this might only be a vulnerability when unp is invoked by a third party product.

Status

Package Ubuntu Release Status
unp 9.10 karmic
Fixed 1.0.14
9.04 jaunty
Fixed 1.0.14
8.10 intrepid
Fixed 1.0.14
8.04 LTS hardy
Fixed 1.0.14
7.10 gutsy Ignored end of life, was needed
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life


Access our resources on patching vulnerabilities