Back to search
CVE-2014-9622
Published: Jan 21, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.freedesktop.org/show_bug.cgi?id=66670
x_refsource_CONFIRM
https://bugs.gentoo.org/show_bug.cgi?id=472888
x_refsource_CONFIRM
20141114 xdg-open RCE
mailing-list
x_refsource_FULLDISC
[oss-security] 20150117 Re: CVE Request: xdg-utils: xdg-open: command injection vulnerability
mailing-list
x_refsource_MLIST
62155
third-party-advisory
x_refsource_SECUNIA
71284
vdb-entry
x_refsource_BID
DSA-3131
vendor-advisory
x_refsource_DEBIAN
GLSA-201701-09
vendor-advisory
x_refsource_GENTOO
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now