Vulnerability Bulletins

DSA-4071 sensible-utils - security update

   
Affected software Debian
 
Gabriel Corona reported that sensible-browser from sensible-utils, acollection of small utilities used to sensibly select and spawn anappropriate browser, editor or pager, does not validate strings beforelaunching the program specified by the BROWSER environment variable,potentially allowing a remote attacker to conduct argument-injectionattacks if a user is tricked into processing a specially crafted URL.

More info:

https://www.debian.org/security/2017/dsa-4071