CVE-2017-17520

Priority
Untriaged
Description
** DISPUTED ** tools/url_handler.pl in TIN 2.4.1 does not validate strings
before launching the program specified by the BROWSER environment variable,
which might allow remote attackers to conduct argument-injection attacks
via a crafted URL. NOTE: a third party has reported that this is
intentional behavior, because the documentation states "url_handler.pl was
designed to work together with tin which only issues shell escaped absolute
URLs."
References
Package
Source: tin (LP Ubuntu Debian)
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 17.10 (Artful Aardvark):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
More Information

Updated: 2018-04-28 06:26:43 UTC (commit 14638)