CVE-2014-0479
reportbug - security update
EPSS 2.7%
Description
reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versions and reportbug/checkversions.py.
How to fix CVE-2014-0479
To remediate CVE-2014-0479, upgrade the affected package to a fixed version below.
- Debian/reportbug—upgrade to 6.5.0+nmu1 or later
- Debian/reportbug—upgrade to 4.12.6+deb6u1 or later
- Debian/reportbug—upgrade to 6.4.4+deb7u1 or later
Is CVE-2014-0479 being exploited?
Low — EPSS is 2.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 6.5.0+nmu1
- from 0, < 4.12.6+deb6u1
- from 0, < 6.4.4+deb7u1