Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17521

Опубликовано: 14 дек. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

Отчет

This issue affects the versions of fontforge as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6fontforgeWill not fix
Red Hat Enterprise Linux 7fontforgeWill not fix
Red Hat Enterprise Linux 8fontforgeAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1526142fontforge: Command injetion in help function uiutil.c

EPSS

Процентиль: 58%
0.00363
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

CVSS3: 8.8
nvd
около 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

CVSS3: 8.8
debian
около 8 лет назад

uiutil.c in FontForge through 20170731 does not validate strings befor ...

suse-cvrf
10 месяцев назад

Security update for fontforge

CVSS3: 8.8
github
больше 3 лет назад

uiutil.c in FontForge through 20170731 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than CVE-2017-17534.

EPSS

Процентиль: 58%
0.00363
Низкий

5.3 Medium

CVSS3