examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
{
"binaries": [
{
"binary_name": "kiwi",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-lib",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-live",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-oem-dump",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-oem-repart",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-overlay",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-verity",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-bootloaders",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-containers",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-core",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-disk-images",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-filesystems",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-iso-media",
"binary_version": "9.25.22-1ubuntu1"
},
{
"binary_name": "kiwi-tools",
"binary_version": "9.25.22-1ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "kiwi",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-lib",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-live",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-oem-dump",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-oem-repart",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-overlay",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-dracut-verity",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-bootloaders",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-containers",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-core",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-disk-images",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-filesystems",
"binary_version": "10.2.28-1"
},
{
"binary_name": "kiwi-systemdeps-iso-media",
"binary_version": "10.2.28-1"
}
]
}
{
"binaries": [
{
"binary_name": "kiwi",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-lib",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-live",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-oem-dump",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-oem-repart",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-overlay",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-dracut-verity",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-bootloaders",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-containers",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-core",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-disk-images",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-filesystems",
"binary_version": "10.1.18-1ubuntu1"
},
{
"binary_name": "kiwi-systemdeps-iso-media",
"binary_version": "10.1.18-1ubuntu1"
}
]
}