CVE-2022-32278
13.06.2022, 22:15
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.Enginsight
| Vendor | Product | Version |
|---|---|---|
| xfce | exo | 𝑥 < 4.16.4 |
| xfce | exo | 4.17.0 ≤ 𝑥 < 4.17.2 |
| debian | debian_linux | 9.0 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| exo |
|
References