CVE-2022-32278
published 2022-06-13CVE-2022-32278: XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.51%
71.9th percentile
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | exo | < exo 4.16.4-1 (bookworm) | exo 4.16.4-1 (bookworm) |
| xfce | exo | < 4.16.4 | 4.16.4 |
| xfce | exo | >= 0 < 4.16.0-1+deb11u1 | 4.16.0-1+deb11u1 |
| xfce | exo | >= 0 < 4.16.4-1 | 4.16.4-1 |
| xfce | exo | >= 0 < 4.16.4-1 | 4.16.4-1 |
| xfce | exo | >= 0 < 4.16.4-1 | 4.16.4-1 |
| xfce | exo | >= 4.17.0 < 4.17.2 | 4.17.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Exo vulnerability
vendor_ubuntu·2023-04-11
CVE-2022-32278 Exo vulnerability
Title: Exo vulnerability
Summary: Exo could be made to crash or run programs if it opened a specially crafted
file.
It was discovered that Exo did not properly sanitized desktop files.
A remote attacker could possibly use this issue to to cause a crash or
arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2022-32278: exo - XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execut...
vendor_debian·2022·CVSS 8.8
CVE-2022-32278 [HIGH] CVE-2022-32278: exo - XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execut...
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Scope: local
bookworm: resolved (fixed in 4.16.4-1)
bullseye: resolved (fixed in 4.16.0-1+deb11u1)
forky: resolved (fixed in 4.16.4-1)
sid: resolved (fixed in 4.16.4-1)
trixie: resolved (fixed in 4.16.4-1)
GHSA
GHSA-9xwj-fh68-48fj: XFCE 4
ghsa_unreviewed·2022-06-14
CVE-2022-32278 [HIGH] GHSA-9xwj-fh68-48fj: XFCE 4
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
OSV
CVE-2022-32278: XFCE 4
osv·2022-06-13·CVSS 8.8
CVE-2022-32278 [HIGH] CVE-2022-32278: XFCE 4
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.xfce.org/xfce/exo/-/commit/c71c04ff5882b2866a0d8506fb460d4ef796de9fhttps://lists.debian.org/debian-lts-announce/2022/06/msg00018.htmlhttps://www.debian.org/security/2022/dsa-5164https://gitlab.xfce.org/xfce/exo/-/commit/c71c04ff5882b2866a0d8506fb460d4ef796de9fhttps://lists.debian.org/debian-lts-announce/2022/06/msg00018.htmlhttps://www.debian.org/security/2022/dsa-5164
2022-06-13
Published