Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
{ "binaries": [ { "binary_name": "libgiac0", "binary_version": "1.2.3.57+dfsg1-2build3" }, { "binary_name": "xcas", "binary_version": "1.2.3.57+dfsg1-2build3" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-17526.json"
{ "binaries": [ { "binary_name": "libgiac0", "binary_version": "1.5.0.85+dfsg1-3" }, { "binary_name": "xcas", "binary_version": "1.5.0.85+dfsg1-3" } ] }
{ "binaries": [ { "binary_name": "libgiac0", "binary_version": "1.7.0.39+dfsg2-1build2" }, { "binary_name": "xcas", "binary_version": "1.7.0.39+dfsg2-1build2" } ] }
{ "binaries": [ { "binary_name": "libgiac0t64", "binary_version": "1.9.0.93+dfsg2-2" }, { "binary_name": "xcas", "binary_version": "1.9.0.93+dfsg2-2" } ] }
{ "binaries": [ { "binary_name": "libgiac0t64", "binary_version": "1.9.0.93+dfsg2-3build1" }, { "binary_name": "xcas", "binary_version": "1.9.0.93+dfsg2-3build1" } ] }
{ "binaries": [ { "binary_name": "libgiac0t64", "binary_version": "1.9.0.93+dfsg2-3build2" }, { "binary_name": "xcas", "binary_version": "1.9.0.93+dfsg2-3build2" } ] }