CVE 2012-2085
The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute.
Related bugs and status
CVE-2012-2085 (Candidate) is related to these bugs:
Bug #992613: gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
992613 | gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support | gajim (Ubuntu) | Undecided | Won't Fix | ||
992613 | gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support | gajim (Debian) | Unknown | Fix Released | ||
992613 | gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support | gajim (Ubuntu Lucid) | Medium | Fix Released | ||
992613 | gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support | gajim (Ubuntu Natty) | Low | Fix Released | ||
992613 | gajim: CVE-2012-2093 insecure temporary file creation in LaTeX support | gajim (Ubuntu Oneiric) | Low | Fix Released |
Bug #992618: gajim code execution and sql injection
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
992618 | gajim code execution and sql injection | gajim (Ubuntu) | Undecided | Fix Released | ||
992618 | gajim code execution and sql injection | gajim (Debian) | Unknown | Fix Released | ||
992618 | gajim code execution and sql injection | gajim (Ubuntu Lucid) | Medium | Fix Released | ||
992618 | gajim code execution and sql injection | gajim (Ubuntu Natty) | Medium | Fix Released | ||
992618 | gajim code execution and sql injection | gajim (Ubuntu Oneiric) | Medium | Fix Released |
Bug #999629: Latest update (0.14.1-1ubuntu1.1) broke execution of external commands (including sounds)
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
999629 | Latest update (0.14.1-1ubuntu1.1) broke execution of external commands (including sounds) | gajim (Ubuntu) | Undecided | Fix Released | ||
999629 | Latest update (0.14.1-1ubuntu1.1) broke execution of external commands (including sounds) | gajim (Ubuntu Lucid) | Undecided | Fix Released | ||
999629 | Latest update (0.14.1-1ubuntu1.1) broke execution of external commands (including sounds) | gajim (Ubuntu Natty) | Undecided | Fix Released | ||
999629 | Latest update (0.14.1-1ubuntu1.1) broke execution of external commands (including sounds) | gajim (Ubuntu Oneiric) | Undecided | Fix Released |
See the
CVE page on Mitre.org
for more details.