mint-search-apt : Shell Code injection

Bug #1527891 reported by Bernd Dietzel
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Linux Mint
Fix Committed
Undecided
Unassigned

Bug Description

https://github.com/linuxmint/mintinstall/issues/99

Demo :
in a terminal type in

mint-search-apt "gimp;xeyes"

this will start xeyes but should not.

LinuxMint uses insecure api calls in may python scripts, this is ony one of many.
https://bugs.launchpad.net/linuxmint/+bug/1525636

Revision history for this message
Bernd Dietzel (l-ubuntuone1104) wrote :
Revision history for this message
Gwendal LE BIHAN (gwendal-lebihan-dev) wrote :
Changed in linuxmint:
status: New → Fix Committed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.