First published: Mon Jan 21 2008(Updated: )
Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/1.0.2 | <4. | 4. |
All of | ||
Any of | ||
Mandrake Linux | =2007.1 | |
Mandrake Linux | =2007.1 | |
Mandrake Linux | =2008.0 | |
Mandrake Linux | =2008.0 | |
Gentoo Xdg-utils | <=1.0.2 | |
Mandrake Linux | =2007.1 | |
Mandrake Linux | =2007.1 | |
Mandrake Linux | =2008.0 | |
Mandrake Linux | =2008.0 | |
Gentoo Xdg-utils | <=1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-0386 is classified as a moderate severity vulnerability.
To fix CVE-2008-0386, update xdg-utils to version 1.0.3 or later.
CVE-2008-0386 affects xdg-utils versions 1.0.2 and earlier.
CVE-2008-0386 allows user-assisted remote attackers to execute arbitrary commands.
CVE-2008-0386 can affect Linux systems using vulnerable versions of xdg-utils.