examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.
{
"binaries": [
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-lib"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-live"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-oem-dump"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-oem-repart"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-overlay"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-dracut-verity"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-bootloaders"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-containers"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-core"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-disk-images"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-filesystems"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-systemdeps-iso-media"
},
{
"binary_version": "9.25.22-1ubuntu1",
"binary_name": "kiwi-tools"
}
]
}
{
"binaries": [
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-lib"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-live"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-oem-dump"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-oem-repart"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-overlay"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-dracut-verity"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-bootloaders"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-containers"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-core"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-disk-images"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-filesystems"
},
{
"binary_version": "10.2.28-1",
"binary_name": "kiwi-systemdeps-iso-media"
}
]
}