oss-sec mailing list archives
Re: Net::Ping::External command injections
From: Simon McVittie <smcv () debian org>
Date: Tue, 7 Nov 2017 18:19:04 +0000
On Tue, 07 Nov 2017 at 17:51:27 +0100, Matthias Weckbecker wrote:
Net::Ping::External [0] is prone to command injection vulnerabilities. The issues are roughly 10 (!) years old [1], but the code is still being shipped these days (e.g. in ubuntu artful and debian stretch [2]).
I've reported this to the Debian bug tracking system, https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=881097 In Ubuntu, libnet-ping-external is in the unsupported 'universe' archive area, making it unlikely to be fixed there regardless of its status in Debian.
Or drop this pkg. altogether?
For what it's worth, Debian's archive maintenance software says nothing in unstable, stable or oldstable depends on this package, so there is no particular barrier to removing it (and bugs in it hopefully only affect locally-installed scripts, not anything else in Debian). smcv
Current thread:
- Net::Ping::External command injections Matthias Weckbecker (Nov 07)
- Re: Net::Ping::External command injections Charlie Brady (Nov 07)
- Re: Net::Ping::External command injections Simon McVittie (Nov 07)
- Re: Net::Ping::External command injections Salvatore Bonaccorso (Nov 07)