PT-2013-1321 · Freedesktop.Org+1 · Xdg-Utils+1

John Houwer

·

Published

2013-07-07

·

Updated

2017-07-01

·

CVE-2014-9622

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions xdg-utils version 1.1.0 RC1
Description The issue is related to a lack of input sanitization in the xdg-utils package, which can be exploited by remote attackers to execute arbitrary code in the context of the application via command injection in the URL. This can occur when no supported desktop environment is identified.
Recommendations For xdg-utils version 1.1.0 RC1, consider restricting the use of the xdg-open command with untrusted URL arguments until a patch is available. As a temporary workaround, avoid using xdg-open with potentially malicious URLs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04520
CVE-2014-9622
DLA-217-1
DSA-3131-1
MGASA-2015-0058
SUSE-SU-2015:0271-1
SUSE-SU-2015_0271-1

Affected Products

Suse
Xdg-Utils