9.8
CVSSv3

CVE-2022-45062

Published: 09/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In Xfce xfce4-settings prior to 4.16.4 and 4.17.x prior to 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

xfce xfce4-settings

xfce xfce4-settings 4.17.0

debian debian linux 11.0

fedoraproject fedora 37

Vendor Advisories

Debian Bug report logs - #1023732 xfce4-settings: CVE-2022-45062: argument injection vulnerability in xfce4-mime-helper Package: src:xfce4-settings; Maintainer for src:xfce4-settings is Debian Xfce Maintainers <debian-xfce@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 9 Nov 2022 ...
Robin Peraglie and Johannes Moritz discovered an argument injection bug in the xfce4-mime-helper component of xfce4-settings, which can be exploited using the xdg-open common tool Since xdg-open is used by multiple standard applications for opening links, this bug could be exploited by an attacker to run arbitrary code on an user machine by provid ...