Bug#773085: xdg-utils: command injection vulnerability

2014-12-31 Thread Michael Gilbert
control: tag -1 pending On Sun, Dec 14, 2014 at 12:32 AM, Michael Gilbert wrote: > A command injection issue was disclosed for xdg-open: > http://seclists.org/fulldisclosure/2014/Nov/36 > > Patch for testing here: > https://bugs.freedesktop.org/attachment.cgi?id=109536 Hi, I prepared an update fi

Bug#773085: xdg-utils: command injection vulnerability

2014-12-13 Thread Michael Gilbert
package: src:xdg-utils severity: serious version: 1.0.2+cvs20100307-2 control: tag -1 patch control: forwarded -1 https://bugs.freedesktop.org/show_bug.cgi?id=66670 A command injection issue was disclosed for xdg-open: http://seclists.org/fulldisclosure/2014/Nov/36 Patch for testing here: https:/