Vulnerability Bulletins |
DSA-4071 sensible-utils - security update |
|
| Affected software | Debian |
|
Gabriel Corona reported that sensible-browser from sensible-utils, acollection of small utilities used to sensibly select and spawn anappropriate browser, editor or pager, does not validate strings beforelaunching the program specified by the BROWSER environment variable,potentially allowing a remote attacker to conduct argument-injectionattacks if a user is tricked into processing a specially crafted URL. More info: https://www.debian.org/security/2017/dsa-4071 |
|






