1 results (0.007 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. gozilla.c en GNU GLOBAL 4.8.6 no valida cadenas antes de iniciar el programa especificado por la variable de entorno BROWSER. Esto podría permitir que atacantes remotos lleven a cabo ataques de inyección de argumentos mediante una URL manipulada. • https://security-tracker.debian.org/tracker/CVE-2017-17531 https://security.gentoo.org/glsa/202008-02 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •