The package shutter before version 0.93.1-3 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201611-13 ========================================= Severity: Medium Date : 2016-11-14 CVE-ID : CVE-2015-0854 Package : shutter Type : arbitrary code execution Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package shutter before version 0.93.1-3 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 0.93.1-3. # pacman -Syu "shutter> =0.93.1-3" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== A vulnerability has been discovered in shutter. Using the "Show in folder" menu option while viewing a file with a specially-crafted path allows arbitrary code execution with the permissions of the user running shutter. Impact ===== An attacker is able to use a specially crafted image file to execute arbitrary code by tricking the user into opening it with a specific option. References ========= https://bugs.archlinux.org/task/50735 https://seclists.org/oss-sec/2015/q3/541 https://access.redhat.com/security/cve/CVE-2015-0854 . The Debian Security Bulletin DSA-2017-15 details a critical vulnerability in the network daemon. Promptly update your system to mitigate potential risks.. shutter package, code execution flaw, Arch Linux advisory. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.