reportbug before 6.4.4+deb7u1 and 6.5.x before 6.5.0+nmu1 allows remote attackers to execute arbitrary commands via vectors related to compare_versions and reportbug/checkversions.py.
📦
reportbug
Vendor: reportbug-ng
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
2
Remote Access
Total CVEs
2
Total Indexed
Avg. EPSS
1.01%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.8
CVSS
CVE-2014-0479
RCE
Severity: MEDIUM
4.6
CVSS
CVE-2008-2230
RCE
Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.
Severity: MEDIUM
2.1
CVSS
reportbug before 2.62 creates the .reportbugrc configuration file with world-readable permissions, which allows local users to obtain email smarthost passwords.
Severity: LOW
2.1
CVSS
reportbug 3.2 includes settings from .reportbugrc in bug reports, which exposes sensitive information such as smtpuser and smtppasswd.
Severity: LOW