CVE-2017-17514

boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable
References
Link Resource
https://github.com/jcupitt/nip2/issues/70 Issue Tracking Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2017-17514 Issue Tracking Third Party Advisory
https://github.com/jcupitt/nip2/issues/70 Issue Tracking Third Party Advisory
https://security-tracker.debian.org/tracker/CVE-2017-17514 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:nip2_project:nip2:8.4.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:18

Type Values Removed Values Added
References () https://github.com/jcupitt/nip2/issues/70 - Issue Tracking, Third Party Advisory () https://github.com/jcupitt/nip2/issues/70 - Issue Tracking, Third Party Advisory
References () https://security-tracker.debian.org/tracker/CVE-2017-17514 - Issue Tracking, Third Party Advisory () https://security-tracker.debian.org/tracker/CVE-2017-17514 - Issue Tracking, Third Party Advisory

07 Nov 2023, 02:41

Type Values Removed Values Added
Summary ** DISPUTED ** boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable. boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a software maintainer indicates that this product does not use the BROWSER environment variable

Information

Published : 2017-12-14 16:29

Updated : 2024-11-21 03:18


NVD link : CVE-2017-17514

Mitre link : CVE-2017-17514

CVE.ORG link : CVE-2017-17514


JSON object : View

Products Affected

debian

  • debian_linux

nip2_project

  • nip2
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')