CVE-2017-17531

HIGH

GNU GLOBAL - Argument Injection via BROWSER Environment Variable

Title source: llm
STIX 2.1

Description

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_misc
https://security-tracker.debian.org/tracker/CVE-2017-17531
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202008-02

Scores

CVSS v3 8.8
EPSS 0.0047
EPSS Percentile 64.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-74
Status published
Products (1)
gnu/global 4.8.6
Published Dec 14, 2017
Tracked Since Feb 18, 2026