xdg-utils - (bulletinoct2019)ID: oval:org.secpod.oval:def:2105083 | Date: (C)2019-12-31 (M)2023-12-20 |
Class: PATCH | Family: unix |
The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
Product: |
library/libsoup |
library/liblouis |
image/library/librsvg |
desktop/xdg/xdg-utils |
desktop/pdf-viewer/evince |