Description
Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-14187 | Insufficient validation of untrusted input in Blink's mailto: handling in Google Chrome prior to 59.0.3071.86 for Linux, Windows, and Mac allowed a remote attacker to perform command injection via a crafted HTML page, a similar issue to CVE-2004-0121. For example, characters such as * have an incorrect interaction with xdg-email in xdg-utils, and a space character can be used in front of a command-line argument. |
References
History
No history.
Subscriptions
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2024-08-05T14:47:44.461Z
Reserved: 2017-01-02T00:00:00.000Z
Link: CVE-2017-5078
No data.
Status : Modified
Published: 2017-10-27T05:29:01.143
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-5078
OpenCVE Enrichment
No data.
Weaknesses
EUVD