First published: Thu Dec 14 2017(Updated: )
** DISPUTED ** default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the attack cannot occur because of the argument-parsing behavior of the Tcl exec function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gabber Gabber | =1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-17533 has been disputed, with concerns regarding potential argument-injection attacks.
To mitigate CVE-2017-17533, validate the input strings before using them in any command execution related to the BROWSER environment variable.
CVE-2017-17533 affects Tkabber version 1.1.
CVE-2017-17533 may allow remote attackers to conduct argument-injection attacks through crafted URLs.
The relevance of CVE-2017-17533 as a concern is debated, but users should remain cautious and validate their input handling.