CVE-2017-17520: High severity Debian Tin vulnerability
DISPUTED tools/urlhandler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has reported that this is intentional behavior, because the documentation states "urlhandler.pl was designed to work together with tin which only issues shell escaped absolute URLs."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17520?
CVE-2017-17520 has a moderate severity level as it allows for argument-injection attacks through unvalidated URL handling.
How do I fix CVE-2017-17520?
To fix CVE-2017-17520, ensure you are using a version of TIN that is updated beyond 2.4.1 and correctly validates input from the BROWSER environment variable.
What kind of attacks can CVE-2017-17520 facilitate?
CVE-2017-17520 can facilitate argument-injection attacks which may lead to arbitrary command execution via crafted URLs.
Which versions of TIN are affected by CVE-2017-17520?
CVE-2017-17520 primarily affects TIN version 2.4.1 and earlier versions.
Is CVE-2017-17520 considered an intentional flaw?
Yes, it has been reported that the behavior leading to CVE-2017-17520 may be intentional, indicating a design choice rather than an oversight.