VDB

CVE-2017-17528

CVE-2017-17528 PUBLISHED

backends/platform/sdl/posix/posix.cpp in ScummVM 1.9.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

EPSS 0.53% · 67.6th percentile

Risk Scores

EPSS Score
0.53%
67.6th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSscummvm2.5.1+dfsg-1build2, 0, 2.5.1-0.1
Ubuntu:18.04:LTSscummvm2.0.0+dfsg-1, 0, 1.9.0+dfsg-2
Ubuntu:24.04:LTSscummvm2.8.0+dfsg-1build4, 2.8.0+dfsg-1, 2.7.0+dfsg-1
Ubuntu:25.10scummvm*, 0, 2.9.1+dfsg-1
Ubuntu:20.04:LTSscummvm2.1.0+dfsg1-2, 2.1.0+dfsg1-1, 2.0.0+dfsg-2
Ubuntu:16.04:LTSscummvm0, *, 1.7.0+dfsg-2

Timeline

  • Dec 14, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • May 14, 2022 CVE Updated
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›