USN-2453-1: mime-support vulnerability
7 January 2015
run-mailcap could be made to run programs as your login if it opened a specially crafted file.
Releases
Packages
- mime-support - MIME support programs
Details
Timothy D. Morgan discovered that the run-mailcap tool incorrectly filtered
certain shell metacharacters in filenames. If a user or automated system
were tricked into opening a file with a specially-crafted filename, a
remote attacker could possibly execute arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 14.10
Ubuntu 14.04
Ubuntu 12.04
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.