The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the name of an LZMA-compressed file.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/94931 | vdb entry third party advisory |
http://seclists.org/oss-sec/2016/q4/666 | issue tracking mailing list third party advisory |
https://lists.debian.org/debian-lts-announce/2016/12/msg00020.html | issue tracking mailing list vendor advisory |
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=848132 | issue tracking patch vendor advisory |