Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-17526

Опубликовано: 14 дек. 2017
Источник: debian
EPSS Низкий

Описание

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
giacunfixedpackage

Примечания

  • https://sources.debian.org/src/giac/1.2.3.57+dfsg1-2/src/Input.cc/?hl=68#L77

EPSS

Процентиль: 66%
0.01221
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
nvd
больше 8 лет назад

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

CVSS3: 8.8
github
около 4 лет назад

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

EPSS

Процентиль: 66%
0.01221
Низкий