First published: Thu Dec 14 2017(Updated: )
af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/abiword | <=3.0.2-8<=3.0.4~dfsg-3<=3.0.5~dfsg-3.2 | |
AbiWord | =3.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17529 is considered a medium severity vulnerability due to its potential for argument-injection attacks.
To fix CVE-2017-17529, upgrade to AbiWord version 3.0.2-9 or later.
CVE-2017-17529 can lead to remote attackers conducting argument-injection attacks using crafted URLs.
AbiWord versions 3.0.2-2 and earlier are affected by CVE-2017-17529.
Yes, CVE-2017-17529 is particularly relevant for Debian users running the affected versions of AbiWord.