[Bug 1072186] New: VUL-0: CVE-2017-17523: lilypond: lilypond-invoke-editor does not validate strings before launching the program specified by the BROWSER environment variable