Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
BID:33165
Info
Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
| Bugtraq ID: | 33165 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 03 2009 12:00AM |
| Updated: | Jan 08 2009 03:42PM |
| Credit: | Manuel Reimer |
| Vulnerable: |
Xdg-utils Xdg-utils 0 |
| Not Vulnerable: | |
Discussion
Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
Xdg-utils is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
This BID is being retired as a duplicate of the vulnerability covered in BID 33137 (Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability).
Xdg-utils is prone to a remote command-execution vulnerability because it fails to sufficiently validate user input.
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected application.
This BID is being retired as a duplicate of the vulnerability covered in BID 33137 (Mozilla Firefox xdg-open 'mailcap' File Remote Code Execution Vulnerability).
Exploit / POC
Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Retired: Xdg-utils mailcap Fake MIME Type Remote Command Execution Vulnerability
References:
References:
- Using xdg-open in mailcap causes serious hole in Firefox! (Xdg-utils)
- Xdg-utils Homepage (Xdg-utils)