The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2453-1 gajim security update
Debian DSA Debian DSA DSA-2453-2 gajim regression
EUVD EUVD EUVD-2012-2091 The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribute.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T19:17:27.938Z

Reserved: 2012-04-04T00:00:00

Link: CVE-2012-2085

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2012-08-28T17:55:04.453

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-2085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.