CVE-2009-0068: Code Injection
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0068?
CVE-2009-0068 has a moderate severity as it can lead to remote code execution through improper MIME type handling.
How do I fix CVE-2009-0068?
To fix CVE-2009-0068, ensure that xdg-utils is updated to a version that addresses this vulnerability.
Which software is affected by CVE-2009-0068?
CVE-2009-0068 affects xdg-utils version 1.0 when interacting with certain MIME types.
Can CVE-2009-0068 be exploited through Firefox?
Yes, CVE-2009-0068 can be exploited through Firefox when it sends a file with a dangerous MIME type to xdg-open.
What are the potential impacts of CVE-2009-0068?
The potential impacts of CVE-2009-0068 include unauthorized execution of arbitrary code on the affected system.