CVE-2014-9622
xdg-utils - security update
EPSS 1.7%
Description
Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.
How to fix CVE-2014-9622
To remediate CVE-2014-9622, upgrade the affected package to a fixed version below.
- Debian/xdg-utils—upgrade to 1.1.0~rc1+git20111210-7.3 or later
- Debian/xdg-utils—upgrade to 1.0.2+cvs20100307-2+deb6u1 or later
- Debian/xdg-utils—upgrade to 1.1.0~rc1+git20111210-6+deb7u2 or later
Is CVE-2014-9622 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 1.1.0~rc1+git20111210-7.3
- from 0, < 1.0.2+cvs20100307-2+deb6u1
- from 0, < 1.1.0~rc1+git20111210-6+deb7u2