Description
Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.
Affected products
References
- VENDOR_ADVISORYhttp://secunia.com/advisories/28574
- VENDOR_ADVISORYhttp://www.ubuntu.com/usn/usn-572-1
- VENDOR_ADVISORYhttp://packages.debian.org/changelogs/pool/main/a/apt-listchanges/apt-listchanges_2.82/changelog
- MISChttp://git.madism.org/?p=apt-listchanges.git%3Ba=commitdiff%3Bh=1bcfbf3dc55413bb83a1782dc9a54515a963fb32
- VENDOR_ADVISORYhttp://secunia.com/advisories/28513
- VENDOR_ADVISORYhttp://www.debian.org/security/2008/dsa-1465
- MISChttp://www.securityfocus.com/bid/27331