CVE-2015-1877: Command Injection
Published Feb 11, 2015
·Updated
The opengenericxdgmime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
Affected Software
5 affected componentsFixes available
debian/xdg-utils
1.1.3-1+deb10u11.1.3-4.1
debian/xdg-utils<=1.0.2+cvs20100307-2, <=1.1.0~rc1+git20111210-7.3
1.1.0~rc1+git20111210-7.41.1.0~rc1+git20111210-6+deb7u31.0.2+cvs20100307-2+deb6u1
Freedesktop xdg-utils=1.1.0-rc1
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jun 2, 2021
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2015-1877?
CVE-2015-1877 is classified as a high severity vulnerability that allows remote command execution.
2
How do I fix CVE-2015-1877?
To remediate CVE-2015-1877, update the xdg-utils package to version 1.1.3-1+deb10u1 or later.
3
What versions of xdg-utils are affected by CVE-2015-1877?
CVE-2015-1877 affects xdg-utils versions up to and including 1.1.0~rc1+git20111210-7.3.
4
Could CVE-2015-1877 be exploited remotely?
Yes, CVE-2015-1877 can be exploited by remote attackers through crafted files.
5
Which operating systems are impacted by CVE-2015-1877?
CVE-2015-1877 impacts various versions of Debian GNU/Linux including version 7.0 and 8.0.