Bug#1013129: exo: CVE-2022-32278

2022-06-18 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On Fri, 2022-06-17 at 17:08 +0200, Moritz Mühlenhoff wrote: > The following vulnerability was published for exo. > > CVE-2022-32278[0]: > > XFCE 4.16 allows attackers to execute arbitrary code because xdg-open > > can execute a .desktop file on an

Bug#1013129: exo: CVE-2022-32278

2022-06-17 Thread Moritz Mühlenhoff
Source: exo X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerability was published for exo. CVE-2022-32278[0]: | XFCE 4.16 allows attackers to execute arbitrary code because xdg-open | can execute a .desktop file on an attacker-controlled FTP server.