RSS   Vulnerabilities for 'Xdg-utils'   RSS

2009-01-07
 
CVE-2009-0068

CWE-94
 

 
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

 

 >>> Vendor: Freedesktop 23 Products
Policykit
DBUS
Dbus1.0
Dbus1.1.0
Scratchbox2
Xdg-utils
Udisks
Dbus-glib
Telepathy gabble
Colord
Libdbus
Spice-gtk
Poppler
Polkit
Virglrenderer
Systemd
Libpoppler
Accountsservice
Libice
Libbsd
Gst-plugins-bad
Libinput
Freetype demo programs


Copyright 2024, cxsecurity.com

 

Back to Top