Bug 7735 - newsbeuter CLI RSS feed
Summary: newsbeuter CLI RSS feed
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: New RPM package request (show other bugs)
Version: Cauldron
Hardware: x86_64 Linux
Priority: Normal enhancement
Target Milestone: ---
Assignee: All Packagers
QA Contact:
URL: http://newsbeuter.org/index.html
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2012-10-08 12:06 CEST by thomas bjo
Modified: 2017-09-20 10:33 CEST (History)
3 users (show)

See Also:
Source RPM: newsbeuter
CVE:
Status comment:


Attachments

Description thomas bjo 2012-10-08 12:06:20 CEST
Newsbeuter is a RSS reader for the Konsole/terminal. It makes the RSS "light" and can be read directly in the terminal.
Good for mobile phone access via SSH etc. Or simply for checking the news in the terminal.
Manuel Hiebel 2012-11-11 00:46:25 CET

Source RPM: http://rpm.pbone.net/index.php3/stat/4/idpl/18535359/dir/mandriva_2011/com/newsbeuter-debug-2.5-1-mdv2011.0.i586.rpm.html => newsbeuter

Comment 1 Klava Petrenko 2014-02-17 16:00:55 CET
Good program.

CC: (none) => abbuyy
Hardware: i586 => x86_64

Klava Petrenko 2014-02-17 16:02:12 CET

Version: Cauldron => 4

Marja Van Waes 2015-09-21 10:40:39 CEST

CC: (none) => marja11
Version: 4 => Cauldron
Severity: normal => enhancement

Comment 2 Samuel Verschelde 2016-10-11 20:54:19 CEST
Assigning this package request to all packagers collectively. On a voluntary basis, one of them might want to integrate it to the distribution and maintain it for bug and security fixes.

You might also want to join the packager team to maintain this piece of software: see https://wiki.mageia.org/en/Becoming_a_Mageia_Packager

Assignee: bugsquad => pkg-bugs

Comment 3 Zombie Ryushu 2017-09-20 10:33:12 CEST
It was discovered that podbeuter, the podcast fetcher in newsbeuter, a text-mode RSS feed reader, did not properly escape the name of the media enclosure (the podcast file), allowing a remote attacker to run an arbitrary shell command on the client machine. This is only exploitable if the file is also played in podbeuter.

So if we ever package this, 

https://www.debian.org/security/2017/dsa-3977

CC: (none) => zombie_ryushu


Note You need to log in before you can comment on or make changes to this bug.