Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

John Houwer

#42762de 56,330
6.8CVSS total
Vulnerabilidades · 1
PT-2013-1321
6.8
2013-07-07
Freedesktop.Org · Xdg-Utils · CVE-2014-9622
**Name of the Vulnerable Software and Affected Versions** xdg-utils version 1.1.0 RC1 **Description** The issue is related to a lack of input sanitization in the xdg-utils package, which can be exploited by remote attackers to execute arbitrary code in the context of the application via command injection in the URL. This can occur when no supported desktop environment is identified. **Recommendations** For xdg-utils version 1.1.0 RC1, consider restricting the use of the xdg-open command with untrusted URL arguments until a patch is available. As a temporary workaround, avoid using xdg-open with potentially malicious URLs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.