CVE-2017-17520

Priority
Description
** DISPUTED ** tools/url_handler.pl in TIN 2.4.1 does not validate strings
before launching the program specified by the BROWSER environment variable,
which might allow remote attackers to conduct argument-injection attacks
via a crafted URL. NOTE: a third party has reported that this is
intentional behavior, because the documentation states "url_handler.pl was
designed to work together with tin which only issues shell escaped absolute
URLs."
Package
Source: tin (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
More Information

Updated: 2019-01-14 21:25:06 UTC (commit 51f9b73af244ba86b9321e46e526586c25a8e060)