CVE-2015-0854

high
Published 2016-12-29 · Modified 2026-05-06
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2
9.3
VIR risk
7.8

Description

App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-0854

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugs.launchpad.net/shutter/+bug/1495163

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201611-13

OS impact

OSVersionStatusFixed in
arch archfixed0.93.1-3
debian debianbookwormfixed0.93.1-1
debian debianforkyfixed0.93.1-1
debian debiansidfixed0.93.1-1
debian debiantrixiefixed0.93.1-1

Application impact

VendorProductVersionsFixed
shutter-projectshutter{"endIncluding":"0.93.1"}

References

CWEs

CWE-19

Verify integrity in audit chain (admin only). AS-IS.