Opened 4 years ago

Closed 4 years ago

Last modified 4 years ago

#16655 closed enhancement (fixed)

exo-4.16.4

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 11.2
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Bruce Dubbs, 4 years ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 4 years ago

4.16.4

  • exo-open : Only execute local .desktop files

comment:3 by Bruce Dubbs, 4 years ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

cb49b59fe7 Update to librsvg-2.54.4.
3006d70923 Update to exo-4.16.4.

comment:4 by Douglas R. Reno, 4 years ago

Priority: normal → elevated

CVE-2022-32278

CVE-2022-32278

This patch prevents executing possibly malicious .desktop files
from online sources (ftp://, http:// etc.).

See ​https://gitlab.xfce.org/xfce/exo/-/commit/cc047717c3b5efded2cc7bd419c41a3d1f1e48b6

Note: See TracTickets for help on using tickets.