Bug#881205: backintime: CVE-2017-16667: shell injection in notify-send

2017-11-08 Thread Salvatore Bonaccorso
Control: found -1 1.0.36-1 Hi On Wed, Nov 08, 2017 at 09:02:11PM +0100, Salvatore Bonaccorso wrote: > Please adjust the affected versions in the BTS as needed. Looks to be present as well in 1.0.36-1+deb8u1, but in notify/plugins/notifyplugin.py. Regards, Salvatore

Bug#881205: backintime: CVE-2017-16667: shell injection in notify-send

2017-11-08 Thread Salvatore Bonaccorso
Source: backintime Version: 1.1.12-2 Severity: grave Tags: patch security upstream Forwarded: https://github.com/bit-team/backintime/issues/834 Hi, the following vulnerability was published for backintime. CVE-2017-16667[0]: | backintime (aka Back in Time) before 1.1.24 did improper | escaping/q