CVE-2017-18266

Impact:
Low
Public Date:
2017-11-18
CWE:
CWE-88
Bugzilla:
1578767: CVE-2017-18266 xdg-utils: Argument injection vulnerability in open_envvar() function

The MITRE CVE dictionary describes this issue as:

The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.

Find out more about CVE-2017-18266 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This issue did not affect the versions of xdg-utils as shipped with Red Hat Enterprise Linux 6 and 7.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 4.4
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction Required
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 xdg-utils Not affected
Red Hat Enterprise Linux 6 xdg-utils Not affected

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.