Python version reported by reportbug, a debian tool for bug reporting was incorrect (not PEP440 compliant) and may break unreleated software like pip, a python package manager, used for local development of python packages. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3666-1
Reportbug, a tool designed to make the reporting of bugs in Debian easier, was further enhanced to automatically detect bug reports for potential regressions caused by a security update. After user confirmation an additional email with a copy of the report will be . Package : reportbug Version : 6.6.3+deb8u2 Debian Bug : 878088 Reportbug, a tool designed to make the reporting of bugs in Debian easier, was further enhanced to automatically detect bug reports for potential regressions caused by a security update. After user confirmation an additional email with a copy of the report will be sent to the debian-lts mailing list. This change requires two new dependencies, python-requests and python-apt. For Debian 8 "Jessie", this problem has been fixed in version 6.6.3+deb8u2. We recommend that you upgrade your reportbug packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update the reportbug package to version 6.6.3+deb8u2 to enhance security vulnerability tracking in Debian.. Debian Reportbug Update, Bug Reporting Tool, Debian Security Fixes. . Severity: Critical. LinuxSecurity.com Team
Jakub Wilk discovered a remote command execution flaw in reportbug, a tool to report bugs in the Debian distribution. A man-in-the-middle attacker could put shell metacharacters in the version number allowing arbitrary code execution with the privileges of the user running . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2997-1
Get the latest Linux and open source security news straight to your inbox.