CVE-2017-17512

sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
VendorProductVersion
sensible-utils_projectsensible-utils
𝑥
< 0.0.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
sensible-utils
bullseye
0.0.14
fixed
bookworm
0.0.17+nmu1
fixed
sid
0.0.24
fixed
trixie
0.0.24
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
sensible-utils
artful
Fixed 0.0.10ubuntu0.1
released
zesty
ignored
xenial
Fixed 0.0.9ubuntu0.16.04.1
released
trusty
Fixed 0.0.9ubuntu0.14.04.1
released