Vulnerability Bulletins

DSA-4211 xdg-utils - security update

   
Affected software Debian
 
Gabriel Corona discovered that xdg-utils, a set of tools for desktopenvironment integration, is vulnerable to argument injection attacks. Ifthe environment variable BROWSER in the victim host has a "%s" and thevictim opens a link crafted by an attacker with xdg-open, the maliciousparty could manipulate the parameters used by the browser when opened.This manipulation could set, for example, a proxy to which the networktraffic could be intercepted for that particular execution.

More info:

https://www.debian.org/security/2018/dsa-4211