In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
References
Link | Resource |
---|---|
https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/55e3c5fb667e96ad1412cf249879262b369d28d7 | Patch Vendor Advisory |
https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/f34a92a84f96268ad24a7a13fd5edc9f1d526110 | Patch Vendor Advisory |
https://gitlab.xfce.org/xfce/xfce4-settings/-/tags | Release Notes Vendor Advisory |
https://gitlab.xfce.org/xfce/xfce4-settings/-/issues/390 | Broken Link |
https://www.debian.org/security/2022/dsa-5296 | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XGTGTTPFHDUB3EZHVKDK4H32QUUYPPFF/ | Mailing List Third Party Advisory |
Information
Published : 2022-11-08 23:15
Updated : 2023-02-03 11:15
NVD link : CVE-2022-45062
Mitre link : CVE-2022-45062
JSON object : View
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Products Affected
debian
- debian_linux
xfce
- xfce4-settings
fedoraproject
- fedora