The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
| Software | From | Fixed in |
|---|---|---|
| freedesktop / xdg-utils | 1.1.0-rc1 | 1.1.0-rc1.x |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 7.0 | 7.0.x |