MGASA-2015-0058

Source
https://advisories.mageia.org/MGASA-2015-0058.html
Import Source
https://advisories.mageia.org/MGASA-2015-0058.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0058
Related
Published
2015-02-11T20:47:51Z
Modified
2015-02-11T20:37:52Z
Summary
Updated xdg-utils packages fix CVE-2014-9622
Details

Updated xdg-utils package fixes security vulnerability:

John Houwer discovered a way to cause xdg-open, a tool that automatically opens URLs in a user's preferred application, to execute arbitrary commands remotely (CVE-2014-9622).

The xdg-utils has been updated to a much more recent snapshot, and has been patched to fix this issue.

References
Credits

Affected packages

Mageia:4 / xdg-utils

Package

Name
xdg-utils
Purl
pkg:rpm/mageia/xdg-utils?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.0-0.0.rc3.3.1.mga4

Ecosystem specific

{
    "section": "core"
}