The file preview functionality in Sketch 0.6.12 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an encapsulated Postscript (EPS) file.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/4296 | vdb entry patch |
http://securitytracker.com/id?1003818 | vdb entry patch |
http://sketch.sourceforge.net/oldnews.html#N1 | |
http://www.iss.net/security_center/static/8469.php | vdb entry patch |