[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4211-1 xdg-utils -- xdg-utils

ID: oval:org.secpod.oval:def:603409Date: (C)2018-05-28   (M)2023-12-20
Class: PATCHFamily: unix




Gabriel Corona discovered that xdg-utils, a set of tools for desktop environment integration, is vulnerable to argument injection attacks. If the environment variable BROWSER in the victim host has a "%s" and the victim opens a link crafted by an attacker with xdg-open, the malicious party could manipulate the parameters used by the browser when opened. This manipulation could set, for example, a proxy to which the network traffic could be intercepted for that particular execution.

Platform:
Debian 8.x
Debian 9.x
Product:
xdg-utils
Reference:
DSA-4211-1
CVE-2017-18266
CVE    1
CVE-2017-18266
CPE    3
cpe:/a:gentoo:xdg-utils
cpe:/o:debian:debian_linux:8.x
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies