The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netrik | Netrik | * | 1.15.4 (including) |
Netrik | Netrik | 1.15.2 (including) | 1.15.2 (including) |
Netrik | Ubuntu | dapper | * |
Netrik | Ubuntu | devel | * |
Netrik | Ubuntu | edgy | * |
Netrik | Ubuntu | feisty | * |
Netrik | Ubuntu | gutsy | * |
Netrik | Ubuntu | hardy | * |
Netrik | Ubuntu | intrepid | * |
Netrik | Ubuntu | jaunty | * |