CVE-2014-9622: Command Injection
Published Jan 21, 2015
·Updated
Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.
Affected Software
2 affected componentsFixes available
debian/xdg-utils
1.1.3-1+deb10u11.1.3-4.1
Gentoo Xdg-utils=1.1.0-rc1
Event History
Jan 21, 2015
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9622?
CVE-2014-9622 is classified as a high severity vulnerability due to the ability it provides for arbitrary code execution.
2
How do I fix CVE-2014-9622?
To fix CVE-2014-9622, update xdg-utils to version 1.1.3 or later.
3
What software is affected by CVE-2014-9622?
CVE-2014-9622 affects xdg-utils version 1.1.0 RC1, particularly in Gentoo and Debian distributions.
4
Can CVE-2014-9622 be exploited remotely?
Yes, CVE-2014-9622 can be exploited by context-dependent attackers through crafted URL arguments.
5
What are the consequences of exploiting CVE-2014-9622?
Exploiting CVE-2014-9622 can allow attackers to execute arbitrary code within the affected environment.