PT-2022-3524 · Exo+4 · Exo+4

Igor Souza

·

Published

2022-06-08

·

Updated

2023-05-21

·

CVE-2022-32278

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions XFCE version 4.16
Description The issue allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server. This is related to errors in security settings in the exo application library of the XFCE desktop environment. Exploitation of the issue may allow a remote attacker to execute arbitrary code using a specially crafted .desktop file.
Recommendations For XFCE version 4.16, to prevent executing possibly malicious .desktop files from online sources, consider updating to a version where this issue has been addressed, which includes changes to prevent the execution of .desktop files from sources like ftp:// or http://. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2040
ALT-PU-2022-2135
ALT-PU-2023-1842
BDU:2022-04307
CVE-2022-32278
DLA-3056-1
DSA-5164-1
MGASA-2022-0238
USN-6008-1

Affected Products

Alt Linux
Linuxmint
Ubuntu
Xfce
Exo