Candidate: CVE-2017-17531 PublicDate: 2017-12-14 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17531 https://sources.debian.org/src/global/4.8.6-2/gozilla/gozilla.c/#L269 https://security-tracker.debian.org/tracker/CVE-2017-17531 Description: gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_global: upstream_global: released (6.6.1-1) precise/esm_global: DNE trusty_global: ignored (reached end-of-life) trusty/esm_global: DNE (trusty was needed) xenial_global: ignored (end of standard support, was needed) zesty_global: ignored (reached end-of-life) artful_global: ignored (reached end-of-life) bionic_global: not-affected (6.6.2-1) cosmic_global: not-affected (6.6.2-1) disco_global: not-affected (6.6.2-1) eoan_global: not-affected (6.6.2-1) focal_global: not-affected (6.6.2-1) groovy_global: not-affected (6.6.2-1) hirsute_global: not-affected (6.6.2-1) impish_global: not-affected (6.6.2-1) jammy_global: not-affected (6.6.2-1) devel_global: not-affected (6.6.2-1)