Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-17524

Опубликовано: 14 дек. 2017
Источник: debian
EPSS Низкий

Описание

library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
swi-prologunfixedpackage

Примечания

  • https://sources.debian.org/src/swi-prolog/7.2.3+dfsg-1/library/www_browser.pl/?hl=68#L68

  • In wheezy it is technically possible to trigger an argument injection

  • vulnerability however it is quoted in an unusual way which makes it highly

  • unlikely that it going to be.

EPSS

Процентиль: 67%
0.00545
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
nvd
около 8 лет назад

library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
github
больше 3 лет назад

library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

EPSS

Процентиль: 67%
0.00545
Низкий