FS#4504 - Beagle -
Attached to Project:
Arch Linux
Opened by James Fryman (jfryman) - Monday, 24 April 2006, 15:21 GMT
Last edited by Tobias Powalowski (tpowa) - Monday, 24 April 2006, 17:14 GMT
Opened by James Fryman (jfryman) - Monday, 24 April 2006, 15:21 GMT
Last edited by Tobias Powalowski (tpowa) - Monday, 24 April 2006, 17:14 GMT
|
Details
Chris Evans discovered that while indexing, Beagle will
build certain
command lines in an insecure manner. When Beagle executes external helper applications, it is possible to cause beagle to execute arbitrary commands as the user running beagle. Please see https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=189282 for more information Beagle 0.2.5 has been released to patch this hole. |
This task depends upon
Comment by James Fryman (jfryman) -
Monday, 24 April 2006, 15:25 GMT
Bug improperly submitted to 'System' - Should be assigned to
'Extra'