USN-4585-1: Newsbeuter vulnerabilities

15 October 2020

Newsbeuter could be made to crash or run programs as your login if it opened a malicious file.

Releases

Packages

  • newsbeuter - open-source RSS/Atom feed reader for text terminals

Details

It was discovered that Newsbeuter didn't handle the command line input
properly. An remote attacker could use it to ran remote code by crafting
a special input file. (CVE-2017-12904)

It was discovered that Newsbeuter didn't handle metacharacters in its
filename properly. An remote attacker could use it to ran remote code by
crafting a special filename. (CVE-2017-14500)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 16.04

In general, a standard system update will make all the necessary changes.