LWN.net Logo

uzbl: arbitrary command execution

Package(s):uzbl CVE #(s):CVE-2010-2809
Created:August 23, 2010 Updated:August 25, 2010
Description: From the CVE entry:

The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

Alerts:
Fedora FEDORA-2010-12276 2010-08-07
Fedora FEDORA-2010-12260 2010-08-07

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds