ZeroHour

CVE-2017-17526

CVSS 3.0
8.8 high
EPSS
1%p67
Published
()
Modified
Description

Input.cc in Bernard Parisse Giac 1.2.3.57 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

Vendors
giac project
Products
giac
Weakness
CWE-74
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.