First published: Wed Nov 09 2022(Updated: )
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/xfce4-settings | 4.12.4-1 4.16.0-1+deb11u1 4.18.2-1 4.18.3-1 | |
xfce4-settings | <4.16.4 | |
xfce4-settings | =4.17.0 | |
Debian | =11.0 | |
Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-45062 is a vulnerability in Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, which allows for argument injection in xfce4-mime-helper.
CVE-2022-45062 has a severity rating of critical with a CVSS score of 9.8.
The affected software versions include xfce4-settings 4.12.4-1, 4.16.0-1+deb11u1, 4.18.2-1, and 4.18.3-1 on Debian, as well as xfce4-settings up to version 4.16.4 and version 4.17.0.
To fix CVE-2022-45062, it is recommended to update Xfce xfce4-settings to version 4.16.4 or newer, or version 4.17.1 or newer if using the 4.17.x branch.
You can find more information about CVE-2022-45062 at the following references: [1] [2] [3].