The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xdg-utils | May 27, 2018 | May 10, 2018 |
| Huawei Euleros 2_0_sp3 | — | Upgrade xdg-utils | Apr 30, 2021 | May 10, 2018 |
| Oracle Solaris | — | Upgrade library/libsoup to version 2.57.1-11.4.15.0.1.2.0 on Solaris 11.4Upgrade desktop/xdg/xdg-utils to version 1.1.3-11.4.15.0.1.2.0 on Solaris 11.4Upgrade desktop/pdf-viewer/evince to version 3.25.4-11.4.15.0.1.2.0 on Solaris 11.4Upgrade library/liblouis to version 3.5.0-11.4.15.0.1.2.0 on Solaris 11.4Upgrade image/library/librsvg to version 2.40.16-11.4.15.0.1.2.0 on Solaris 11.4 | Nov 20, 2019 | May 10, 2018 |
| Suse | — | Upgrade xdg-utils | Jun 6, 2018 | May 10, 2018 |
| Ubuntu | — | Upgrade xdg-utils | May 23, 2018 | May 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub