CVE-2015-1877

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
02/06/2021
Last modified:
14/06/2021

Description

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:freedesktop:xdg-utils:1.1.0:rc1:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*