PT-2022-27396 · Xfce+3 · Xfce4-Mime-Helper+4

Johannes Moritz

+1

·

Published

2022-11-08

·

Updated

2023-06-06

·

CVE-2022-45062

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xfce4-settings versions 4.16.3 and earlier, 4.17.x before 4.17.1
Description There is an argument injection issue in the xfce4-mime-helper from the xfce4-settings package. This issue allows for argument injection, which can potentially be exploited.
Recommendations For versions 4.16.3 and earlier, update to version 4.16.4 or later. For versions 4.17.x before 4.17.1, update to version 4.17.1 or later.

Exploit

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3023
ALT-PU-2022-3101
ALT-PU-2022-3168
CVE-2022-45062
DSA-5296-1
MGASA-2022-0471
OESA-2022-2105
USN-6141-1

Affected Products

Alt Linux
Linuxmint
Ubuntu
Xfce4-Mime-Helper
Xfce4-Settings