First published: Mon Jun 13 2022(Updated: )
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/exo | <=4.16.3-1<=4.16.0-1<=0.12.4-1 | 4.16.4-1 4.16.0-1+deb11u1 0.12.4-1+deb10u1 4.18.0-1 |
debian/exo | 0.12.4-1+deb10u1 4.16.0-1+deb11u1 4.18.0-1 | |
XFCE exo | <4.16.4 | |
XFCE exo | >=4.17.0<4.17.2 | |
Debian GNU/Linux | =9.0 | |
Debian GNU/Linux | =10.0 | |
Debian GNU/Linux | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-32278.
The severity rating of CVE-2022-32278 is high.
Attackers can exploit CVE-2022-32278 by executing arbitrary code using xdg-open to open a .desktop file on an attacker-controlled FTP server.
The affected software versions of CVE-2022-32278 are XFCE 4.16.4-1, 4.16.0-1+deb11u1, 0.12.4-1+deb10u1, and 4.18.0-1.
To fix CVE-2022-32278, update XFCE to version 4.16.4-1, 4.16.0-1+deb11u1, 0.12.4-1+deb10u1, or 4.18.0-1.