Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-17521

Опубликовано: 14 дек. 2017
Источник: debian
EPSS Низкий

Описание

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
fontforgefixed1:20201107~dfsg-1package

Примечания

  • https://sources.debian.org/src/fontforge/1:20170731%7Edfsg-1/fontforgeexe/uiutil.c/#L285

  • Code removed in https://github.com/fontforge/fontforge/commit/029bbb606b6502d651454fee996f8dd3ea15fa94 (20200314)

EPSS

Процентиль: 77%
0.01834
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

CVSS3: 5.3
redhat
больше 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

CVSS3: 8.8
nvd
больше 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

suse-cvrf
больше 1 года назад

Security update for fontforge

CVSS3: 8.8
github
больше 4 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

EPSS

Процентиль: 77%
0.01834
Низкий