Vulnerability Description
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Xdg-Utils | 1.0 |
| Mozilla | Firefox | All versions |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2009/01/06/1
- http://www.securityfocus.com/bid/33137
- https://bugs.freedesktop.org/show_bug.cgi?id=19377
- http://www.openwall.com/lists/oss-security/2009/01/06/1
- http://www.securityfocus.com/bid/33137
- https://bugs.freedesktop.org/show_bug.cgi?id=19377
FAQ
What is CVE-2009-0068?
CVE-2009-0068 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open...
How severe is CVE-2009-0068?
CVE-2009-0068 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-0068?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Xdg-Utils, Mozilla Firefox.