~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-17535

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2017-17535
2
 
PublicDate: 2017-12-14
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17535
5
 
 https://sources.debian.org/src/gjots2/2.4.1-2/lib/gui.py/?hl=2188#L2188
6
 
 https://security-tracker.debian.org/tracker/CVE-2017-17535
7
 
Description:
8
 
 lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before
9
 
 launching the program specified by the BROWSER environment variable, which
10
 
 might allow remote attackers to conduct argument-injection attacks via a
11
 
 crafted URL.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
Priority: untriaged
16
 
Discovered-by:
17
 
Assigned-to:
18
 
 
19
 
 
20
 
Patches_gjots2:
21
 
upstream_gjots2: needs-triage
22
 
precise/esm_gjots2: DNE
23
 
trusty_gjots2: needs-triage
24
 
xenial_gjots2: needs-triage
25
 
zesty_gjots2: ignored (reached end-of-life)
26
 
artful_gjots2: needs-triage
27
 
bionic_gjots2: needs-triage
28
 
devel_gjots2: needs-triage