CVE-2014-0479: Canonical Reportbug

Medium severity, CVSS 6.8. EPSS: 2.7% chance of exploitation in the next 30 days.

reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versions and reportbug/checkversions.py.

Affected products

  • Canonical Reportbug: up to and including 6.5.0
  • Debian Reportbug: up to and including 6.4.4

Published 2014-08-06. Last modified 2026-06-17.