CVE-2014-9622

medium
Published 2015-01-21 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-9622

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.1.0~rc1+git20111210-7.3
debian debianbullseyefixed1.1.0~rc1+git20111210-7.3
debian debianforkyfixed1.1.0~rc1+git20111210-7.3
debian debiansidfixed1.1.0~rc1+git20111210-7.3
debian debiantrixiefixed1.1.0~rc1+git20111210-7.3

Application impact

VendorProductVersionsFixed
gentooxdg-utils1.1.0

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.