CVE-2013-2516: Remote command execution
(updated )
The package fileutils does not sanitize input on URLs passed to CutyCapt. If a URL contains shell characters, such as a ;
followed by a command, a remote attacker can execute a command on the client’s system if they are enticed to click an encoded URL.
References
Detect and mitigate CVE-2013-2516 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →