CVE-2022-32278: High severity xfce exo vulnerability
Published Jun 13, 2022
·Updated
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Affected Software
7 affected componentsFixes available
debian/exo<=4.16.3-1, <=4.16.0-1, <=0.12.4-1
4.16.4-14.16.0-1+deb11u10.12.4-1+deb10u14.18.0-1
debian/exo
0.12.4-1+deb10u14.16.0-1+deb11u14.18.0-1
Xfce Exo<4.16.4
Xfce Exo>=4.17.0<4.17.2
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Remediation
Event History
Jun 13, 2022
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this XFCE vulnerability?
The vulnerability ID is CVE-2022-32278.
2
What is the severity rating of CVE-2022-32278?
The severity rating of CVE-2022-32278 is high.
3
How can attackers exploit CVE-2022-32278?
Attackers can exploit CVE-2022-32278 by executing arbitrary code using xdg-open to open a .desktop file on an attacker-controlled FTP server.
4
Which software versions are affected by CVE-2022-32278?
The affected software versions of CVE-2022-32278 are XFCE 4.16.4-1, 4.16.0-1+deb11u1, 0.12.4-1+deb10u1, and 4.18.0-1.
5
How can I fix CVE-2022-32278?
To fix CVE-2022-32278, update XFCE to version 4.16.4-1, 4.16.0-1+deb11u1, 0.12.4-1+deb10u1, or 4.18.0-1.