CVE-2017-12904: Debian Linux
High severity, CVSS 8.8. EPSS: 6.4% chance of exploitation in the next 30 days.
Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Newsbeuter Newsbeuter: version 0.7 only; version 0.8 only; version 0.8.1 only; version 0.8.2 only; version 0.9 only; version 0.9.1 only; …
Published 2017-08-23. Last modified 2026-06-17.