lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
{ "binaries": [ { "binary_name": "gjots2", "binary_version": "2.4.1-2" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-17535.json"
{ "binaries": [ { "binary_name": "gjots2", "binary_version": "2.4.1-5" } ] }
{ "binaries": [ { "binary_name": "gjots2", "binary_version": "3.1.9-0ubuntu1" } ] }
{ "binaries": [ { "binary_name": "gjots2", "binary_version": "3.1.9-0ubuntu2" } ] }