Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0068

Опубликовано: 07 янв. 2009
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:freedesktop:xdg-utils:1.0:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01379
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94

Связанные уязвимости

ubuntu
почти 17 лет назад

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

debian
почти 17 лет назад

Interaction error in xdg-open allows remote attackers to execute arbit ...

github
больше 3 лет назад

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

EPSS

Процентиль: 80%
0.01379
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-94