[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-5296-1 xfce4-settings -- xfce4-settings

ID: oval:org.secpod.oval:def:610299Date: (C)2022-12-23   (M)2023-05-11
Class: PATCHFamily: unix




Robin Peraglie and Johannes Moritz discovered an argument injection bug in the xfce4-mime-helper component of xfce4-settings, which can be exploited using the xdg-open common tool. Since xdg-open is used by multiple standard applications for opening links, this bug could be exploited by an attacker to run arbitrary code on an user machine by providing a malicious PDF file with specifically crafted links.

Platform:
Debian 11.x
Product:
xfce4-helpers
xfce4-settings
Reference:
DSA-5296-1
CVE-2022-45062
CVE    1
CVE-2022-45062

© SecPod Technologies