Lorenz Hipp discovered a flaw in exuberant-ctags handling of the tag filename command-line argument. A crafted tag filename specified in the command line or in the configuration file could result in arbitrary command execution.
{ "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro", "binaries": [ { "binary_version": "1:5.9~svn20110310-11ubuntu0.1~esm1", "binary_name": "exuberant-ctags" }, { "binary_version": "1:5.9~svn20110310-11ubuntu0.1~esm1", "binary_name": "exuberant-ctags-dbgsym" } ] }