{"id":"DEBIAN-CVE-2017-17532","details":"examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.","modified":"2026-09-01T20:03:46.307612272Z","published":"2017-12-14T16:29:01.057Z","upstream":["CVE-2017-17532"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2017-17532"}],"affected":[{"package":{"name":"kiwi","ecosystem":"Debian:12","purl":"pkg:deb/debian/kiwi?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["10.1.18-1","10.1.20-1","10.2.10-1","10.2.12-1","10.2.13-1","10.2.16-1","10.2.22-1","10.2.24-1","10.2.26-1","10.2.27-1","10.2.28-1","10.2.31-1","10.2.32-1","10.2.33-1","10.2.36-1","10.2.38-1","10.2.41-1","10.2.42-1","10.2.43-1","10.2.45-1","10.2.9-1","10.3.0-1","10.3.10-1","10.3.4-1","10.3.5-1","10.3.7-1","10.3.9-1","9.24.56-1","9.25.11-1","9.25.12-1","9.25.13-1","9.25.14-1","9.25.17-1","9.25.18-1","9.25.19-1","9.25.20-1","9.25.21-1","9.25.22-1","9.25.5-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17532.json"}},{"package":{"name":"kiwi","ecosystem":"Debian:14","purl":"pkg:deb/debian/kiwi?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.13-1","1.9.13-2","1.9.13-3","1.9.13-4","1.9.15-1","1.9.16-1","1.9.19-1","1.9.19-2","1.9.21-1","1.9.22-1","1.9.22-2","1.9.22-3","1.9.22-4","1.9.22-4.1","1.9.22-4.2","1.9.8-1","1.9.8-2","1.9.8-3","1.9.8-4","1.9.8-5","1.9.8-6","1.9.8-7","1.9.9-1","1.9.9-2","10.1.18-1","10.1.20-1","10.2.10-1","10.2.12-1","10.2.13-1","10.2.16-1","10.2.22-1","10.2.24-1","10.2.26-1","10.2.27-1","10.2.28-1","10.2.31-1","10.2.32-1","10.2.33-1","10.2.36-1","10.2.38-1","10.2.41-1","10.2.42-1","10.2.43-1","10.2.45-1","10.2.9-1","10.3.0-1","10.3.10-1","10.3.4-1","10.3.5-1","10.3.7-1","10.3.9-1","9.24.12-1","9.24.19-1","9.24.20-1","9.24.27-1","9.24.29-1","9.24.30-1","9.24.31-1","9.24.32-1","9.24.35-1","9.24.36-1","9.24.39-1","9.24.43-1","9.24.44-1","9.24.45-1","9.24.48-1","9.24.49-1","9.24.51-1","9.24.54-1","9.24.56-1","9.25.11-1","9.25.12-1","9.25.13-1","9.25.14-1","9.25.17-1","9.25.18-1","9.25.19-1","9.25.20-1","9.25.21-1","9.25.22-1","9.25.5-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17532.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}