Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2008-02-04 15:00
Updated : 2011-03-07 19:04
NVD link : CVE-2008-0386
Mitre link : CVE-2008-0386
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
mandrakesoft
- mandrake_linux
gentoo
- xdg-utils