Bug#791467: plowshare: javascript usage puts user at risk of remote code execution

2015-07-16 Thread plowshare4-bug@discard.email
> I am in the process of packaging the new upstream version of plowshare. > There has been a significant change so that the core framework (of shell > scripts) is kept entirely separate to the scripts which use this API to > implement support for specific external sites.   While separating the core

Bug#791467: plowshare: javascript usage puts user at risk of remote code execution

2015-07-05 Thread plowshare4-bug@discard.email
Package: plowshare4 Version: 1.0.5-1 Severity: grave Tags: security   (Rationale for severity grave: introduces a security hole allowing access to the accounts of users who use the package. plowshare4 is a command-line tool for downloading files from cyberlocker-type sites. For some sites, this req