First published: Thu Dec 14 2017(Updated: )
af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Abisource Abiword | =3.0.2-2 | |
debian/abiword | <=3.0.2-8<=3.0.4~dfsg-3<=3.0.5~dfsg-3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.