Bug#731582: canto: command line injection in urls inside feeds

2013-12-08 Thread Vincent Legout
Hi, the_walrus...@manlymail.net writes: > I have just found a command line injection security vuln in > canto. The program fetches feeds from configured sites, and the > feeds contain URLs that people may want to visit. If a user > starts canto and chooses to go to one URL from one feed, canto >

Bug#731582: canto: command line injection in urls inside feeds

2013-12-06 Thread the_walrus_88
Package: canto Version: 0.7.10-4 Severity: important Tags: security Dear Maintainer, I have just found a command line injection security vuln in canto. The program fetches feeds from configured sites, and the feeds contain URLs that people may want to visit. If a user starts canto and chooses to