First published: Wed Jan 09 2008(Updated: )
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend id, program name and working directory in session management."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xfce xfce4-settings | <=4.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6532 has a moderate severity level due to its potential to allow remote code execution.
To fix CVE-2007-6532, upgrade the Xfce library to version 4.4.2 or later.
CVE-2007-6532 affects the Xfce library version prior to 4.4.2.
Yes, CVE-2007-6532 can be exploited remotely, allowing attackers to execute arbitrary code.
CVE-2007-6532 involves components related to session management, specifically the client ID, program name, and working directory.