CVE-2008-3907

The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
newsbeuternewsbeuter
𝑥
≤ 1.0
newsbeuternewsbeuter
0.1.1
newsbeuternewsbeuter
0.2
newsbeuternewsbeuter
0.3
newsbeuternewsbeuter
0.4
newsbeuternewsbeuter
0.5
newsbeuternewsbeuter
0.6
newsbeuternewsbeuter
0.7
newsbeuternewsbeuter
0.8
newsbeuternewsbeuter
0.8.1
newsbeuternewsbeuter
0.8.2
newsbeuternewsbeuter
0.9
newsbeuternewsbeuter
0.9.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
newsbeuter
intrepid
Fixed 0.9.1-1+lenny3
released
hardy
Fixed 0.7-1ubuntu0.1
released
gutsy
ignored
feisty
dne
dapper
dne