CVE-2008-0302

NameCVE-2008-0302
DescriptionUntrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1465-2
NVD severityhigh (attack range: local)
Debian/oldoldstablenot vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apt-listchanges (PTS)squeeze2.85.7+squeeze1fixed
wheezy2.85.11fixed
stretch, jessie, sid2.85.13+nmu1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apt-listchangessource(unstable)2.82medium
apt-listchangessourceetch2.72.5etch2highDSA-1465-2
apt-listchangessourcesarge(not affected)

Notes

[sarge] - apt-listchanges <not-affected> (Vulnerable code not present)
see http://git.madism.org/?p=apt-listchanges.git;a=commitdiff;h=1bcfbf3dc55413bb83a1782dc9a54515a963fb32

Search for package or bug name: Reporting problems