Improper Neutralization of Special Elements used in an OS Command in the podcast playback function of Podbeuter in Newsbeuter 0.3 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure (i.e., a podcast file) that includes shell metacharacters in its filename, related to pb_controller.cpp and queueloader.cpp, a different vulnerability than CVE-2017-12904.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade newsbeuter | Oct 26, 2017 | Sep 17, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 17, 2017 |
| Debian | — | Upgrade newsbeuter | Sep 19, 2017 | Sep 17, 2017 |
| Gentoo Linux | — | Upgrade net-news/newsbeuter. | Mar 12, 2018 | Sep 17, 2017 |
| Suse | — | Upgrade newsbeuter-langUpgrade newsbeuter-debugsourceUpgrade newsbeuterUpgrade newsbeuter-debuginfo | Jan 26, 2018 | Sep 17, 2017 |
| Ubuntu | — | Upgrade newsbeuter | Oct 16, 2020 | Sep 17, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub