CVE-2017-17533

default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the attack cannot occur because of the argument-parsing behavior of the Tcl exec function
References
Link Resource
https://security-tracker.debian.org/tracker/CVE-2017-17533 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:tkabber_project:tkabber:1.1:*:*:*:*:*:*:*

History

07 Nov 2023, 02:41

Type Values Removed Values Added
Summary ** DISPUTED ** default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the attack cannot occur because of the argument-parsing behavior of the Tcl exec function. default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated that the attack cannot occur because of the argument-parsing behavior of the Tcl exec function

Information

Published : 2017-12-14 16:29

Updated : 2024-04-11 00:57


NVD link : CVE-2017-17533

Mitre link : CVE-2017-17533

CVE.ORG link : CVE-2017-17533


JSON object : View

Products Affected

tkabber_project

  • tkabber
CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')