Loading
Generated remediation guidance and an executive summary. No account required.
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
Use CWE-77, Freedesktop vendor hub and Xdg-Utils product page to widen CVE-2015-1877 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-18266, CVE-2022-4055 and CVE-2009-0068 for nearby disclosures in the same product family.