CSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file when creating a new record.
{ "binaries": [ { "binary_name": "hamster-applet", "binary_version": "3.0.2-3" }, { "binary_name": "hamster-time-tracker", "binary_version": "3.0.2-3" } ] }
{ "binaries": [ { "binary_name": "hamster-time-tracker", "binary_version": "3.0.3-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "hamster-time-tracker", "binary_version": "3.0.3-3" } ] }