Vulnerability Bulletins |
DSA-4211 xdg-utils - security update |
|
| Affected software | Debian |
|
Gabriel Corona discovered that xdg-utils, a set of tools for desktopenvironment integration, is vulnerable to argument injection attacks. Ifthe environment variable BROWSER in the victim host has a "%s" and thevictim opens a link crafted by an attacker with xdg-open, the maliciousparty could manipulate the parameters used by the browser when opened.This manipulation could set, for example, a proxy to which the networktraffic could be intercepted for that particular execution. More info: https://www.debian.org/security/2018/dsa-4211 |
|






