CVE-2015-1877
02.06.2021, 17:15
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
| Vendor | Product | Version |
|---|---|---|
| freedesktop | xdg-utils | 1.1.0:rc1 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References