MGASA-2015-0058
Dashboard / Vulnerabilities / MGASA-2015-0058
Summary: Updated xdg-utils packages fix CVE-2014-9622
Details: Updated xdg-utils package fixes security vulnerability: John Houwer discovered a way to cause xdg-open, a tool that automatically opens URLs in a user's preferred application, to execute arbitrary commands remotely (CVE-2014-9622). The xdg-utils has been updated to a much more recent snapshot, and has been patched to fix this issue.
References: https://advisories.mageia.org/MGASA-2015-0058.html, https://bugs.mageia.org/show_bug.cgi?id=14932, https://www.debian.org/security/2015/dsa-3131
Affected packages
Package
Name: xdg-utils
Purl: pkg:rpm/mageia/xdg-utils?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -1.1.0-0.0.rc3.3.1.mga4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
