Vulnerability Name:

CVE-2017-18266 (CCN-143217)

Assigned:2018-05-10
Published:2018-05-10
Updated:2018-06-14
Summary:The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-74
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2017-18266

Source: CCN
Type: Bugzilla – Bug 103807
(CVE-2017-18266) - Argument injection in xdg-open open_envvar

Source: MISC
Type: Issue Tracking, Patch
https://bugs.freedesktop.org/show_bug.cgi?id=103807

Source: CCN
Type: xdg-utils Web site
xdg-utils

Source: MISC
Type: Release Notes
https://cgit.freedesktop.org/xdg/xdg-utils/commit/?id=5647afb35e4bcba2060148e1a2a47bc43cc240f2

Source: MISC
Type: Patch
https://cgit.freedesktop.org/xdg/xdg-utils/commit/?id=ce802d71c3466d1dbb24f2fe9b6db82a1f899bcb

Source: MISC
Type: Release Notes
https://cgit.freedesktop.org/xdg/xdg-utils/tree/ChangeLog

Source: XF
Type: UNKNOWN
xdgutils-cve201718266-code-exec(143217)

Source: MLIST
Type: Third Party Advisory
[debian-lts-announce] 20180525 [SECURITY] [DLA 1384-1] xdg-utils security update

Source: UBUNTU
Type: Third Party Advisory
USN-3650-1

Source: DEBIAN
Type: Third Party Advisory
DSA-4211

Vulnerable Configuration:Configuration 1:
  • cpe:/a:freedesktop:xdg-utils:*:*:*:*:*:*:*:* (Version < 1.1.3)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201718266
    V
    CVE-2017-18266
    2023-06-22
    oval:org.opensuse.security:def:7683
    P
    libtirpc-devel-1.2.6-150300.3.17.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7830
    P
    xdg-utils-1.1.3+20210805-150500.1.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:7705
    P
    libyaml-0-2-0.1.7-1.17 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:588
    P
    Security update for helm (Important) (in QA)
    2022-09-21
    oval:org.opensuse.security:def:3822
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3224
    P
    libopenvswitch-2_11-0-2.11.1-1.75 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:123966
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3400
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:124371
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94854
    P
    xdg-utils-1.1.3+20201113-150400.1.4 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:292
    P
    python3-setuptools-40.5.0-6.3.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:335
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:387
    P
    xdg-utils-1.1.3+20201113-150400.1.4 on GA media (Moderate)
    2022-06-10
    oval:org.opensuse.security:def:6338
    P
    Security update for gcc48 (Moderate)
    2022-06-08
    oval:org.opensuse.security:def:113589
    P
    xdg-utils-1.1.3+20201113-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:6292
    P
    Security update for python2-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:8728
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:916
    P
    Security update for libvirt (Important)
    2022-01-04
    oval:org.opensuse.security:def:8885
    P
    Security update for p11-kit (Important)
    2021-12-22
    oval:org.opensuse.security:def:49303
    P
    Security update for python-Babel (Important)
    2021-12-22
    oval:org.opensuse.security:def:6270
    P
    Security update for logback (Important)
    2021-12-17
    oval:org.opensuse.security:def:6724
    P
    Security update for the Linux Kernel (Live Patch 24 for SLE 15) (Important)
    2021-12-14
    oval:org.opensuse.security:def:6262
    P
    Security update for ImageMagick (Moderate)
    2021-12-10
    oval:org.opensuse.security:def:7221
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:100685
    P
    (Important)
    2021-12-01
    oval:org.opensuse.security:def:8866
    P
    Security update for netcdf (Important)
    2021-11-30
    oval:org.opensuse.security:def:9049
    P
    Security update for busybox (Important)
    2021-10-27
    oval:org.opensuse.security:def:8851
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:6981
    P
    Security update for the Linux Kernel (Live Patch 18 for SLE 15 SP1) (Important)
    2021-10-14
    oval:org.opensuse.security:def:106975
    P
    xdg-utils-1.1.3+20201113-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:61091
    P
    Security update for the Linux Kernel (Important)
    2021-09-23
    oval:org.opensuse.security:def:89832
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61572
    P
    libsndfile-devel-1.0.28-5.5.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96797
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61677
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61595
    P
    libxkbcommon-devel-0.8.2-3.3.1 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71418
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61571
    P
    libsmi-0.4.8-1.29 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103487
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:63216
    P
    librelp-devel-1.2.15-1.15 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71188
    P
    gdk-pixbuf-loader-rsvg-2.42.3-1.49 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:1264
    P
    Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3) (Important)
    2021-09-16
    oval:org.opensuse.security:def:43506
    P
    Security update for libcroco (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:9036
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:9027
    P
    Security update for spectre-meltdown-checker (Moderate)
    2021-08-27
    oval:org.opensuse.security:def:9018
    P
    Security update for libass (Important)
    2021-08-20
    oval:org.opensuse.security:def:69903
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:6956
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15 SP1) (Important)
    2021-08-17
    oval:org.opensuse.security:def:47109
    P
    opensc-0.13.0-1.107 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47812
    P
    libxcb-dri2-0-1.10-4.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48024
    P
    gnome-shell-3.20.4-77.23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:15221
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47970
    P
    chrony-2.3-5.6.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47274
    P
    groff-1.22.2-5.287 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48235
    P
    logrotate-3.11.0-2.14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47438
    P
    libz1-1.2.8-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48108
    P
    libexempi3-2.2.1-5.7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48041
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47920
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47366
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48266
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47570
    P
    bzip2-1.0.6-29.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47110
    P
    openslp-2.0.0-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47514
    P
    tcpdump-4.9.0-13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48337
    P
    w3m-0.5.3.git20161120-161.3.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48341
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47662
    P
    libFLAC++6-1.3.0-11.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47874
    P
    radvd-1.9.7-2.12 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46949
    P
    giflib-progs-5.0.5-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47124
    P
    perl-HTML-Parser-3.71-1.145 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47728
    P
    libjpeg-turbo-1.5.3-31.7.4 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:14800
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47810
    P
    libwavpack1-4.60.99-5.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:87961
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47939
    P
    MozillaFirefox-68.1.0-109.92.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47142
    P
    quagga-0.99.22.1-12.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48170
    P
    libpcsclite1-1.8.10-7.6.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47245
    P
    dstat-0.7.2-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63355
    P
    libwsman-devel-2.6.7-3.9.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63122
    P
    aws-cli-1.18.117-8.11.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:72094
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62361
    P
    yast2-security-4.3.16-1.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:101111
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62353
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62037
    P
    btrfsmaintenance-0.4.2-1.11 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63020
    P
    libgit2-28-0.28.4-1.28 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62231
    P
    libtspi1-0.3.14-6.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:8628
    P
    Security update for nodejs8 (Important)
    2021-08-05
    oval:org.opensuse.security:def:59512
    P
    Security update for curl (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:59513
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:8804
    P
    Security update for dbus-1 (Important)
    2021-07-12
    oval:org.opensuse.security:def:8615
    P
    Security update for arpwatch (Important)
    2021-06-28
    oval:org.opensuse.security:def:8985
    P
    Security update for dovecot23 (Important)
    2021-06-22
    oval:org.opensuse.security:def:8606
    P
    Security update for caribou (Important)
    2021-06-17
    oval:org.opensuse.security:def:12452
    P
    gdk-pixbuf-lang-2.34.0-19.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12503
    P
    libHX28-3.18-1.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12318
    P
    perl-Config-IniFiles-2.82-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12195
    P
    libevent-2_0-5-2.0.21-4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71122
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12751
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46814
    P
    perl-Cyrus-IMAP-2.3.18-35.71 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12516
    P
    libXfont2-2-2.0.3-1.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12333
    P
    python-pyOpenSSL-16.0.0-2.3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48679
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36558
    P
    rubygem-activerecord-3_2-3.2.12-0.11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71075
    P
    policycoreutils-2.6-3.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46828
    P
    python-libxml2-2.9.1-10.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12203
    P
    libgif6-32bit-5.0.5-12.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48733
    P
    libgadu3-1.11.4-1.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12352
    P
    strongswan-5.1.3-25.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36569
    P
    silc-toolkit-1.1.7-7.23.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:78047
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:8597
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:46813
    P
    perl-Config-IniFiles-2.82-3.14 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12225
    P
    liblzo2-2-2.08-1.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61134
    P
    cairo-devel-1.15.10-2.22 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12427
    P
    dbus-1-1.8.22-29.10.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36557
    P
    rubygem-activemodel-3_2-3.2.12-0.5.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61184
    P
    hardlink-1.0+git.e66999f-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61381
    P
    xdg-utils-20170508-3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12494
    P
    kernel-default-4.12.14-94.41.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:12271
    P
    libssh2-1-1.4.3-19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61214
    P
    libXrender-devel-0.9.10-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:8960
    P
    Security update for ceph (Important)
    2021-06-02
    oval:org.opensuse.security:def:44545
    P
    Security update for dhcp (Important)
    2021-06-01
    oval:org.opensuse.security:def:8383
    P
    Security update for rubygem-actionpack-5_1 (Important)
    2021-05-26
    oval:org.opensuse.security:def:9709
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:8758
    P
    Security update for lz4 (Important)
    2021-05-19
    oval:org.opensuse.security:def:60255
    P
    Security update for python3 (Important)
    2021-05-17
    oval:org.opensuse.security:def:8315
    P
    Security update for drbd-utils (Moderate)
    2021-05-11
    oval:org.opensuse.security:def:64488
    P
    Security update for ceph (Important)
    2021-05-04
    oval:org.opensuse.security:def:6881
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) (Important)
    2021-04-28
    oval:org.opensuse.security:def:8564
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:8736
    P
    Security update for spamassassin (Important)
    2021-04-13
    oval:org.opensuse.security:def:9687
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:70008
    P
    Security update for ruby2.5 (Important)
    2021-03-24
    oval:org.opensuse.security:def:7023
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP1) (Important)
    2021-03-17
    oval:org.opensuse.security:def:7243
    P
    Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important)
    2021-03-17
    oval:org.opensuse.security:def:6732
    P
    Security update for the Linux Kernel (Live Patch 19 for SLE 15) (Important)
    2021-03-17
    oval:org.opensuse.security:def:7014
    P
    Security update for the Linux Kernel (Important)
    2021-03-09
    oval:org.opensuse.security:def:54767
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:60448
    P
    Security update for perl-File-Path (Moderate)
    2021-02-12
    oval:org.opensuse.security:def:59535
    P
    Security update for openvswitch (Important)
    2021-02-03
    oval:org.opensuse.security:def:93972
    P
    (Moderate)
    2021-02-02
    oval:org.opensuse.security:def:8539
    P
    Security update for flac (Moderate)
    2020-12-24
    oval:org.opensuse.security:def:6847
    P
    Security update for the Linux Kernel (Live Patch 14 for SLE 15 SP1) (Important)
    2020-12-07
    oval:org.opensuse.security:def:67735
    P
    Security update for the Linux Kernel (Live Patch 20 for SLE 15) (Important)
    2020-12-07
    oval:org.opensuse.security:def:63305
    P
    squid-4.11-5.17.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13154
    P
    python-doc-2.7.13-28.31.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63388
    P
    apache-commons-daemon-1.0.15-2.51 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116909
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62571
    P
    libopenjpeg1-1.5.2-2.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62005
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13213
    P
    xdg-utils-20140630-6.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61764
    P
    gstreamer-plugins-good-1.16.2-1.85 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:13176
    P
    screen-4.0.4-23.3.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62890
    P
    bsh2-2.0.0.b6-3.102 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48975
    P
    bash-lang-4.3-83.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71746
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49029
    P
    libpodofo0_9_2-0.9.2-3.9.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63254
    P
    apache2-mod_security2-2.9.2-1.34 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107351
    P
    xdg-utils-1.1.3+20190413-1.24 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:59695
    P
    Security update for python-setuptools (Important)
    2020-12-02
    oval:org.opensuse.security:def:21867
    P
    Security update for LibVNCServer (Critical)
    2020-12-01
    oval:org.opensuse.security:def:54210
    P
    gnome-shell on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37458
    P
    guile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6570
    P
    coreutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38517
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6385
    P
    libid3tag0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:8464
    P
    libxcb-dri2-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37344
    P
    tomcat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9288
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52562
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:36789
    P
    apache-commons-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:43977
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:6800
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:22248
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37726
    P
    apache-commons-beanutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45183
    P
    Security update for xerces-j2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53637
    P
    Security update for perl (Important)
    2020-12-01
    oval:org.opensuse.security:def:37074
    P
    automake on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6552
    P
    alsa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49357
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36978
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:8337
    P
    ibus-chewing on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53385
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:37256
    P
    libsrtp1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55413
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:43518
    P
    Security update for jasper (Important)
    2020-12-01
    oval:org.opensuse.security:def:22354
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:55160
    P
    lcms on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73343
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:21966
    P
    Security update for perl (Important)
    2020-12-01
    oval:org.opensuse.security:def:54316
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37618
    P
    mailman on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60967
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:6583
    P
    dbus-1-glib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64401
    P
    libvpx4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6400
    P
    libmikmod3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53870
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:37372
    P
    aaa_base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56436
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:52702
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:36890
    P
    libXxf86vm1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:44094
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:7032
    P
    libevent-2_0-5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:45231
    P
    Security update for xdg-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52539
    P
    Security update for munge (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:22287
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:37765
    P
    cyrus-sasl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53659
    P
    Security update for ghostscript (Important)
    2020-12-01
    oval:org.opensuse.security:def:37210
    P
    libjasper1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60749
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53670
    P
    Security update for dovecot23 (Important)
    2020-12-01
    oval:org.opensuse.security:def:44408
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:43622
    P
    Security update for xmltooling (Important)
    2020-12-01
    oval:org.opensuse.security:def:22366
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:23034
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:22030
    P
    Security update for python3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:54482
    P
    gnome-settings-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37677
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:61053
    P
    Security update for sane-backends (Important)
    2020-12-01
    oval:org.opensuse.security:def:56510
    P
    Security update for xdg-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:21812
    P
    Security update for the Linux Kernel (Live Patch 31 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:59949
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:6419
    P
    libpoppler-glib8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53944
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37416
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52940
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:36947
    P
    libsndfile1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:44283
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:7045
    P
    libgssglue1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66560
    P
    libxslt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6862
    P
    wdiff on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54967
    P
    ntp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37793
    P
    gdm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38054
    P
    rrdtool on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67835
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53799
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37311
    P
    python-cupshelpers on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60869
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:9266
    P
    syslog-service on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53636
    P
    Security update for mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:8430
    P
    libpng16-16 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53778
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:44459
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:8307
    P
    file on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:43787
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:22396
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:22070
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:36979
    P
    openvpn on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60134
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:6494
    P
    python-pyOpenSSL on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53982
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66652
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53113
    P
    Security update for python-urllib3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37037
    P
    unixODBC on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:44353
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73225
    P
    libssh-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38096
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55041
    P
    xlockmore on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37837
    P
    lftp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:21820
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:54037
    P
    liblzo2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37368
    P
    yast2-users on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6561
    P
    bind-libs-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:8445
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37305
    P
    pigz on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:44488
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38475
    P
    rtkit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52540
    P
    Security update for slurm (Important)
    2020-12-01
    oval:org.opensuse.security:def:36653
    P
    libecpg6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:43902
    P
    Security update for libssh2_org (Important)
    2020-12-01
    oval:org.opensuse.security:def:6754
    P
    libsilc-1_1-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:22123
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:54875
    P
    libjasper1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:23063
    P
    Security update for xdg-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36990
    P
    perl-Config-IniFiles on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:6519
    P
    telepathy-idle on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54063
    P
    libsmi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:53219
    P
    Security update for qemu (Important)
    2020-12-01
    oval:org.opensuse.security:def:37197
    P
    libgcrypt20 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:43507
    P
    Security update for gdk-pixbuf (Low)
    2020-12-01
    oval:org.opensuse.security:def:55079
    P
    cpp48 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55339
    P
    p7zip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:84859
    P
    Security update for xdg-utils (Moderate)
    2018-06-04
    oval:org.opensuse.security:def:79144
    P
    Security update for xdg-utils (Moderate)
    2018-06-04
    oval:com.ubuntu.artful:def:201718266000
    V
    CVE-2017-18266 on Ubuntu 17.10 (artful) - medium.
    2018-05-10
    oval:com.ubuntu.bionic:def:201718266000
    V
    CVE-2017-18266 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-10
    oval:com.ubuntu.bionic:def:2017182660000000
    V
    CVE-2017-18266 on Ubuntu 18.04 LTS (bionic) - medium.
    2018-05-10
    oval:com.ubuntu.trusty:def:201718266000
    V
    CVE-2017-18266 on Ubuntu 14.04 LTS (trusty) - medium.
    2018-05-10
    oval:com.ubuntu.xenial:def:2017182660000000
    V
    CVE-2017-18266 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-10
    oval:com.ubuntu.xenial:def:201718266000
    V
    CVE-2017-18266 on Ubuntu 16.04 LTS (xenial) - medium.
    2018-05-10
    BACK
    freedesktop xdg-utils *
    debian debian linux 7.0
    debian debian linux 8.0
    debian debian linux 9.0
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    canonical ubuntu linux 17.10
    canonical ubuntu linux 18.04