/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a Run a plugin action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Shutter | Shutter-project | * | 0.93.1 (including) |
Shutter | Ubuntu | artful | * |
Shutter | Ubuntu | bionic | * |
Shutter | Ubuntu | esm-apps/xenial | * |
Shutter | Ubuntu | precise | * |
Shutter | Ubuntu | trusty | * |
Shutter | Ubuntu | xenial | * |
Shutter | Ubuntu | yakkety | * |
Shutter | Ubuntu | zesty | * |