The open_generic_xdg_mime function in xdg-open in xdg...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Jun 2, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 29, 2023
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
References