CVE-2017-17512 PUBLISHED

sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.

EPSS 0.59% · 69.1th percentile

Risk Scores

EPSS Score
0.59%
69.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsensible-utils0, 0.0.9
Ubuntu:14.04:LTSsensible-utils0, 0.0.9

Timeline

References

Open in Interactive Console →