CVE-2022-32278
13.06.2022, 22:15
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.Enginsight
Vendor | Product | Version |
---|---|---|
xfce | exo | 𝑥 < 4.16.4 |
xfce | exo | 4.17.0 ≤ 𝑥 < 4.17.2 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
exo |
|
References