{"id":"CVE-2017-12904","details":"Improper Neutralization of Special Elements used in an OS Command in bookmarking function of Newsbeuter versions 0.7 through 2.9 allows remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL.","modified":"2026-02-24T11:19:47.032150Z","published":"2017-08-23T14:29:00.393Z","references":[{"type":"WEB","url":"https://groups.google.com/forum/#%21topic/newsbeuter/iFqSE7Vz-DE"},{"type":"WEB","url":"https://usn.ubuntu.com/4585-1/"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3947"},{"type":"ADVISORY","url":"https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307"},{"type":"ADVISORY","url":"https://github.com/akrennmair/newsbeuter/issues/591"},{"type":"REPORT","url":"https://github.com/akrennmair/newsbeuter/issues/591"},{"type":"FIX","url":"https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/akrennmair/newsbeuter","events":[{"introduced":"0"},{"fixed":"96e9506ae9e252c548665152d1b8968297128307"}]}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12904.json","vanir_signatures":[{"id":"CVE-2017-12904-80defa35","signature_type":"Function","signature_version":"v1","source":"https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307","target":{"file":"src/controller.cpp","function":"controller::bookmark"},"deprecated":false,"digest":{"function_hash":"156371956141367904438567274571704191043","length":1137}},{"target":{"file":"src/controller.cpp"},"deprecated":false,"digest":{"line_hashes":["311467814947250909956345134156606465782","120649832345985744059501555645473888522","291634685458980627202111577571935776043","69626142850719159396634039256131327469","108602646767993423147163902786916057536","98085112480429494262981916468034871801","92970788905403075723020112092901087587","252124518186464253228361430297539845061","254514588870447734634416090126986229927"],"threshold":0.9},"id":"CVE-2017-12904-a213a0e6","signature_type":"Line","signature_version":"v1","source":"https://github.com/akrennmair/newsbeuter/commit/96e9506ae9e252c548665152d1b8968297128307"}]}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}