XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Exo | Xfce | * | 4.16.4 (excluding) |
Exo | Xfce | 4.17.0 (including) | 4.17.2 (excluding) |
Exo | Ubuntu | bionic | * |
Exo | Ubuntu | esm-apps/bionic | * |
Exo | Ubuntu | esm-apps/focal | * |
Exo | Ubuntu | esm-apps/jammy | * |
Exo | Ubuntu | esm-apps/xenial | * |
Exo | Ubuntu | focal | * |
Exo | Ubuntu | impish | * |
Exo | Ubuntu | jammy | * |
Exo | Ubuntu | kinetic | * |
Exo | Ubuntu | lunar | * |
Exo | Ubuntu | mantic | * |
Exo | Ubuntu | trusty/esm | * |