First published: Thu Dec 14 2017(Updated: )
library/www_browser.pl in SWI-Prolog 7.2.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Swi-prolog Swi-prolog | =7.2.3 | |
debian/swi-prolog | <=8.0.2+dfsg-3+deb10u1<=8.2.4+dfsg-1<=9.0.4+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.