ZeroHour

CVE-2017-17514

CVSS 3.1
8.8 high
EPSS
2%p76
Published
()
Modified
Description

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable

Vendors
nip2 projectdebian
Products
nip2, debian linux
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.