Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2009-0068
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2009-0068

Description:
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.

CVE Status:
Candidate

References:

MLIST
  http://www.openwall.com/lists/oss-security/2009/01/06/1

MISC

BID
  33137


Return to the previous page.