CVE-2015-0854

NameCVE-2015-0854
DescriptionApp/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-769-1
Debian Bugs798862

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
shutter (PTS)bookworm0.99.2-4fixed
sid, trixie0.99.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
shuttersourcewheezy0.88.3-1+deb7u1DLA-769-1
shuttersourcejessie0.92-0.1+deb8u1
shuttersource(unstable)0.93.1-1low798862

Notes

[squeeze] - shutter <no-dsa> (Minor issue)
https://bugs.launchpad.net/shutter/+bug/1495163

Search for package or bug name: Reporting problems