Hi! I ran into https://www.exploit-db.com/exploits/41435/?rss and had a look if we apply patches to close that vulnerability. While our files/shutter-0.93.1-insecure_use_of_system.patch seems to be related, there are more places calling system, e.g. system("xdg-email $mail $user_data"); or system("nautilus-sendto $user_data &"); that look scary (from just a quick look) and that are patched in other distros, e.g. see https://anonscm.debian.org/cgit/collab-maint/shutter.git/tree/debian/patches/fix-perl-system-calls#n234. Please have a closer look. Thank you!
References: https://www.cvedetails.com/cve/CVE-2016-10081/ https://bugs.launchpad.net/shutter/+bug/1652600
@ Maintainer(s): Please add https://anonscm.debian.org/cgit/collab-maint/shutter.git/tree/debian/patches/fix-perl-system-calls
this should be bumped to 0.94 https://launchpad.net/shutter/0.9x/0.94/+download/shutter-0.94.tar.gz
The package was bumped to 0.94.3 Is anything left todo?
(In reply to Jonas Stein from comment #4) > The package was bumped to 0.94.3 > Is anything left todo? Based on https://salsa.debian.org/perl-team/modules/attic/shutter/-/blob/master/debian/patches/fix-perl-system-calls, I think the current patch in 0.93.1-r3 may be incomplete. It's been applied now: https://bazaar.launchpad.net/~shutter/shutter/devel/revision/1298, which is in 0.94.2. @maintainer(s), please cleanup!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4f4ee7f75329062c350a8508b80b02be691f604e commit 4f4ee7f75329062c350a8508b80b02be691f604e Author: Sebastian Pipping <sping@gentoo.org> AuthorDate: 2020-03-18 18:03:38 +0000 Commit: Sebastian Pipping <sping@gentoo.org> CommitDate: 2020-03-18 18:04:53 +0000 x11-misc/shutter: Drop vulnerable Bug: https://bugs.gentoo.org/610612 Signed-off-by: Sebastian Pipping <sping@gentoo.org> Package-Manager: Portage-2.3.92, Repoman-2.3.20 x11-misc/shutter/Manifest | 1 - x11-misc/shutter/files/shutter-0.90-webphoto.patch | 17 ----- .../shutter-0.93.1-insecure_use_of_system.patch | 19 ----- x11-misc/shutter/shutter-0.93.1-r3.ebuild | 85 ---------------------- 4 files changed, 122 deletions(-)
Package is unstable.