Loading
Generated remediation guidance and an executive summary. No account required.
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
Use CWE-94, Freedesktop vendor hub and Xdg-Utils product page to widen CVE-2009-0068 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2015-1877, CVE-2017-18266 and CVE-2022-4055 for nearby disclosures in the same product family.