1 results (0.026 seconds)

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. af/util/xp/ut_go_file.cpp en AbiWord 3.0.2-2 no valida cadenas antes de iniciar el programa especificado por la variable de entorno BROWSER. Esto podría permitir que atacantes remotos lleven a cabo ataques de inyección de argumentos mediante una URL manipulada. • https://security-tracker.debian.org/tracker/CVE-2017-17529 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •