Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-32563

Опубликовано: 11 мая 2021
Источник: debian

Описание

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
thunarfixed4.16.8-1package
thunarno-dsabusterpackage
thunarno-dsastretchpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2021/05/09/2

  • Fixed by: https://gitlab.xfce.org/xfce/thunar/-/commit/9165a61f95e43cc0b5abf9b98eee2818a0191e0b

  • Regression fix: https://gitlab.xfce.org/xfce/thunar/-/commit/3b54d9d7dbd7fd16235e2141c43a7f18718f5664

  • Regression: https://gitlab.xfce.org/xfce/thunar/-/issues/575

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 4 лет назад

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVSS3: 9.8
nvd
больше 4 лет назад

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

CVSS3: 9.8
fstec
больше 10 лет назад

Уязвимость файлового менеджера Thunar, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании