Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument.
{
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "59.0.3071.109-0ubuntu0.14.04.1186"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "59.0.3071.109-0ubuntu0.14.04.1186"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "59.0.3071.109-0ubuntu0.14.04.1186"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "59.0.3071.109-0ubuntu0.14.04.1186"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "59.0.3071.109-0ubuntu0.14.04.1186"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "chromium-browser",
"binary_version": "59.0.3071.109-0ubuntu0.16.04.1289"
},
{
"binary_name": "chromium-browser-l10n",
"binary_version": "59.0.3071.109-0ubuntu0.16.04.1289"
},
{
"binary_name": "chromium-chromedriver",
"binary_version": "59.0.3071.109-0ubuntu0.16.04.1289"
},
{
"binary_name": "chromium-codecs-ffmpeg",
"binary_version": "59.0.3071.109-0ubuntu0.16.04.1289"
},
{
"binary_name": "chromium-codecs-ffmpeg-extra",
"binary_version": "59.0.3071.109-0ubuntu0.16.04.1289"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "liboxideqt-qmlplugin",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "liboxideqtcore-dev",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "liboxideqtcore0",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "liboxideqtquick-dev",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "liboxideqtquick0",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "oxideqt-codecs",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
},
{
"binary_name": "oxideqt-codecs-extra",
"binary_version": "1.21.5-0ubuntu0.16.04.1"
}
]
}