LWN.net Logo

xdg-utils: arbitrary command execution

Package(s):xdg-utils CVE #(s):CVE-2008-0386
Created:January 31, 2008 Updated:February 22, 2008
Description: From the Gentoo alert: Miroslav Lichvar discovered that the "xdg-open" and "xdg-email" shell scripts do not properly sanitize their input before processing it. A remote attacker could entice a user to open a specially crafted link with a vulnerable application using Xdg-Utils (e.g. an email client), resulting in the execution of arbitrary code with the privileges of the user running the application.
Alerts:
Gentoo 200801-21 2008-01-30
Mandriva MDVSA-2008:031 2007-02-01
SuSE SUSE-SR:2008:004 2008-02-22

(Log in to post comments)

xdg-utils: arbitrary command execution

Posted Feb 7, 2008 18:24 UTC (Thu) by kreutzm (subscriber, #4700) [Link]

Debian Etch is not vulnerable.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.