Bug#898317: xdg-open: Argument injection in xdg-open open_envvar

2018-05-10 Thread Salvatore Bonaccorso
Control: found -1 1.1.0~rc1+git20111210-7.4 The issue seems present as well in earlier version, though in upstream commit 3c2fe9f1ebbfdbffcc9e38a767641805cec3340b this part was refactored.

Bug#898317: xdg-open: Argument injection in xdg-open open_envvar

2018-05-10 Thread Salvatore Bonaccorso
Source: xdg-utils Version: 1.1.1-1 Severity: important Tags: patch security upstream Forwarded: https://bugs.freedesktop.org/show_bug.cgi?id=103807 Hi there is a argument injection vulenrability in xdg-open open_envvar. Details: https://bugs.freedesktop.org/show_bug.cgi?id=103807 https://cgit.f