CVE-2022-45062: Critical severity Xfce xfce4-settings vulnerability
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xfce4-settingsto a version that resolves this vulnerability.Fixed in 4.12.4-1Fixed in 4.16.0-1+deb11u1Fixed in 4.18.2-1Fixed in 4.18.3-1
Event History
Frequently Asked Questions
What is CVE-2022-45062?
CVE-2022-45062 is a vulnerability in Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, which allows for argument injection in xfce4-mime-helper.
How severe is CVE-2022-45062?
CVE-2022-45062 has a severity rating of critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2022-45062?
The affected software versions include xfce4-settings 4.12.4-1, 4.16.0-1+deb11u1, 4.18.2-1, and 4.18.3-1 on Debian, as well as xfce4-settings up to version 4.16.4 and version 4.17.0.
How can I fix CVE-2022-45062?
To fix CVE-2022-45062, it is recommended to update Xfce xfce4-settings to version 4.16.4 or newer, or version 4.17.1 or newer if using the 4.17.x branch.
Where can I find more information about CVE-2022-45062?
You can find more information about CVE-2022-45062 at the following references: [1] [2] [3].