[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4071-1 sensible-utils -- sensible-utils

ID: oval:org.secpod.oval:def:603219Date: (C)2017-12-27   (M)2023-12-20
Class: PATCHFamily: unix




Gabriel Corona reported that sensible-browser from sensible-utils, a collection of small utilities used to sensibly select and spawn an appropriate browser, editor or pager, does not validate strings before launching the program specified by the BROWSER environment variable, potentially allowing a remote attacker to conduct argument-injection attacks if a user is tricked into processing a specially crafted URL.

Platform:
Debian 8.x
Debian 9.x
Product:
sensible-utils
Reference:
DSA-4071-1
CVE-2017-17512
CVE    1
CVE-2017-17512
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:debian:sensible-utils

© SecPod Technologies