lilypond does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks (CVE-2017-17523).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2018-0412.json"