Back

HIGH

xdg-utils: command injection vulnerability due to local variables collision in xdg-open

Published Jun 2, 2021

Description

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of xdg-utils as shipped with Red Hat Enterprise Linux 6 and 7.

Metrics

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner debian
Published Jun 2, 2021
Updated Aug 6, 2024
Reserved Feb 18, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2015