Cybertrion Systems

[2/5] Xdg-utils Command Injection Vulnerabilities

January 31st, 2008 by
[2/5] Xdg-utils Command Injection Vulnerabilities

:Some vulnerabilities have been reported in Xdg-utils, which can be exploited by malicious people to compromise a user’s system.The vulnerabilities are caused due to the "xgd-open" and "xdg-email" scripts not correctly sanitising parameters before using them in a sed call. This can be exploited to inject and execute shell commands if e.g. a malicious URL is passed to the affected scripts.Successful exploitation requires that the scripts are not used in a KDE, Gnome, or XFCE session.The vulnerabilities are reported in version 1.0.2. Other versions may also be affected.Solution:Fixed in the CVS repository:http://webcvs.freedesktop.org/portlan…scripts/xdg-email?r1=1.36&r2=1.37http://webcvs.freedesktop.org/portlan…/scripts/xdg-open?r1=1.32&r2=1.33Provided and/or discovered by:Reported in a Red Hat bug by Miroslav Lichvar.Original Advisory:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2008-0386

Original post by sonia

[2/5] Xdg-utils Command Injection Vulnerabilities

Related Articles:
  • [2/5] Gentoo update for xdg-utils
  • [1/5] util-linux-ng “login” Audit Log Injection Weakness
  • [2/5] rPath update for am-utils
  • [2/5] Gentoo update for am-utils
  • [2/5] rPath update for net-snmp and net-snmp-utils


  • Posted in Advisories - Exploits | | [2/5] Xdg-utils Command Injection Vulnerabilities

    << [3/5] WordPress WassUp Plugin “to_date” SQL Injection Vulnerability | [4/5] SwiftView Viewer ActiveX Control/Plug-in Buffer Overflows >>