Описание
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | released | 1.1.1-1ubuntu3.2 |
| bionic | released | 1.1.2-1ubuntu2.2 |
| devel | released | 1.1.2-1ubuntu3 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [1.1.0~rc1-2ubuntu7.2]] |
| esm-infra/bionic | released | 1.1.2-1ubuntu2.2 |
| esm-infra/xenial | released | 1.1.1-1ubuntu1.16.04.3 |
| precise/esm | DNE | |
| trusty | released | 1.1.0~rc1-2ubuntu7.2 |
| trusty/esm | DNE | trusty was released [1.1.0~rc1-2ubuntu7.2] |
| upstream | needs-triage |
Показывать по
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3
Связанные уязвимости
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does no ...
EPSS
6.8 Medium
CVSS2
8.8 High
CVSS3