{"id":"MGASA-2019-0031","summary":"Updated terminology package fixes security vulnerability CVE-2018-20167","details":"Terminology before 1.3.1 allows Remote Code Execution because popmedia\nis mishandled, as demonstrated by an unsafe \"cat README.md\" command when\n\\e}pn is used. A popmedia control sequence can allow the malicious\nexecution of executable file formats registered in the X desktop share\nMIME types (/usr/share/applications). The control sequence defers\nunknown file types to the handle_unknown_media() function, which\nexecutes xdg-open against the filename specified in the sequence. The\nuse of xdg-open for all unknown file types allows executable file\nformats with a registered shared MIME type to be executed. An attacker\ncan achieve remote code execution by introducing an executable file and\na plain text file containing the control sequence through a fake\nsoftware project (e.g., in Git or a tarball). When the control sequence\nis rendered (such as with cat), the executable file will be run.\n","modified":"2026-04-16T06:23:38.778303549Z","published":"2019-01-11T05:54:06Z","upstream":["CVE-2018-20167"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0031.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=24110"},{"type":"WEB","url":"https://phab.enlightenment.org/rTRM1ac204da9148e7bccb1b5f34b523e2094dfc39e2"}],"affected":[{"package":{"name":"terminology","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/terminology?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.1.0-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0031.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}