MGASA-2022-0238 - Updated exo packages fix security vulnerability Publication date: 24 Jun 2022 URL: https://advisories.mageia.org/MGASA-2022-0238.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-32278 Changed to prevent executing possibly malicious .desktop files from online sources ( http:// etc.). References: - https://bugs.mageia.org/show_bug.cgi?id=30540 - https://gitlab.xfce.org/xfce/exo/-/commit/cc047717c3b5efded2cc7bd419c41a3d1f1e48b6 - https://www.cve.org/CVERecord?id=CVE-2022-32278 SRPMS: - 8/core/exo-4.16.0-1.1.mga8 . Changed to prevent executing possibly malicious .desktop files from online sources ( http:// etc.). References: - https://bugs.mageia.org/show_bug.cgi?id=30540 . Mageia security bulletin MGASA-2022-0238 outlines exo enhancements aimed at thwarting the execution of harmful desktop files.. Mageia Exo Update, Security Advisory, Malicious Files Prevention. . LinuxSecurity.com Team
It was discovered that exo, a support library for the Xfce desktop environment, would allow executing remote .desktop files. In some scenario, an attacker could use this vulnerability to trick an user an execute arbitrary code on the platform with the privileges of that user. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5164-1
Get the latest Linux and open source security news straight to your inbox.