Lucene search

K
cve[email protected]CVE-2009-0068
HistoryJan 07, 2009 - 7:30 p.m.

CVE-2009-0068

2009-01-0719:30:00
CWE-94
web.nvd.nist.gov
23
cve-2009-0068
xdg-open
remote attackers
arbitrary code
mime type
firefox
automatic type detection
.desktop file

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

89.9%

Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

Affected configurations

NVD
Node
freedesktopxdg-utilsMatch1.0
AND
mozillafirefox

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.024 Low

EPSS

Percentile

89.9%