Update to 4.20.6, the latest stable bugfix release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7a1a0e5bd8 2025-11-03 01:37:06.585272+00:00 -------------------------------------------------------------------------------- Name : Thunar Product : Fedora 43 Version : 4.20.6 Release : 1.fc43 URL : https://www.xfce.org/ Summary : Thunar File Manager Description : Thunar is a new modern file manager for the Xfce Desktop Environment. It has been designed from the ground up to be fast and easy-to-use. Its user interface is clean and intuitive, and does not include any confusing or useless options. Thunar is fast and responsive with a good start up time and directory load time. -------------------------------------------------------------------------------- Update Information: Update to 4.20.6, the latest stable bugfix release. -------------------------------------------------------------------------------- ChangeLog: * Sat Oct 25 2025 Kevin Fenzi - 4.20.6-1 - Update to 4.20.6. Fixes rhbz#2406294 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2406294 - Thunar 4.20.6 is available! Fedora's Thunar is significantly out of date https://bugzilla.redhat.com/show_bug.cgi?id=2406294 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7a1a0e5bd8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
A vulnerability has been discovered in Thunar which may lead to arbitrary code execution. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Thunar: Arbitrary Code Execution Date: February 18, 2024 Bugs: #789396 ID: 202402-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Thunar which may lead to arbitrary code execution Background ========== Thunar is a modern file manager for the Xfce Desktop Environment. Thunar has been designed from the ground up to be fast and easy to use. Its user interface is clean and intuitive and does not include any confusing or useless options by default. Thunar starts up quickly and navigating through files and folders is fast and responsive. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ xfce-base/thunar < 4.17.3 > = 4.17.3 Description =========== A vulnerability has been discovered in Thunar. Please review the CVE identifier referenced below for details. Impact ====== When called with a regular file as command line argument, Thunar would delegate to some other program without user confirmation based on the file type. This could be exploited to trigger code execution in a chain of vulnerabilities. Workaround ========== There is no known workaround at this time. Resolution ========== All Thunar users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =xfce-base/thunar-4.17.3" References ========== [ 1 ] CVE-2021-32563 https://nvd.nist.gov/vuln/detail/CVE-2021-32563 Availability ============ This GLSAand any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-20 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution (CVE-2021-32563). . MGASA-2021-0306 - Updated thunar packages fix a security vulnerability Publication date: 30 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0306.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-32563 An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution (CVE-2021-32563). References: - https://bugs.mageia.org/show_bug.cgi?id=28904 - https://www.openwall.com/lists/oss-security/2021/05/09/2 - https://www.openwall.com/lists/oss-security/2021/05/11/3 - https://www.cve.org/CVERecord?id=CVE-2021-32563 SRPMS: - 8/core/thunar-4.16.8-1.mga8 . The latest Thunar 4.16.8 update addresses key security issues, enhancing system stability. Learn more about the identified vulnerabilities and their fixes. Thunar Security Patch, Mageia Update, Code Execution Fix, Mageia Linux Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.