First published: Thu Dec 14 2017(Updated: )
gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/global | 6.6.3-2 6.6.5-1 6.6.9-1 | |
GNU GLOBAL | =4.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17531 is considered a high severity vulnerability due to its potential for argument-injection attacks.
To fix CVE-2017-17531, update to GNU GLOBAL version 6.6.3-2, 6.6.5-1, or 6.6.9-1, or apply relevant patches.
CVE-2017-17531 can allow remote attackers to execute arbitrary commands via crafted URLs, compromising system integrity.
CVE-2017-17531 specifically affects GNU GLOBAL version 4.8.6.
Yes, CVE-2017-17531 is exploitable remotely through crafted URLs targeting the BROWSER environment variable.