An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
When called with a regular file as a command-line argument, it delegates to
a different program (based on the file type) without user confirmation.
This could be used to achieve code execution (CVE-2021-32563).
- https://bugs.mageia.org/show_bug.cgi?id=28904
- https://www.openwall.com/lists/oss-security/2021/05/09/2
- https://www.openwall.com/lists/oss-security/2021/05/11/3
- https://www.cve.org/CVERecord?id=CVE-2021-32563
- 8/core/thunar-4.16.8-1.mga8
Get the latest Linux and open source security news straight to your inbox.