Opened 23 months ago

Closed 23 months ago

Last modified 23 months ago

#16655 closed enhancement (fixed)

exo-4.16.4

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 11.2
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Bruce Dubbs, 23 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: newassigned

comment:2 by Bruce Dubbs, 23 months ago

4.16.4

  • exo-open : Only execute local .desktop files

comment:3 by Bruce Dubbs, 23 months ago

Resolution: fixed
Status: assignedclosed

Fixed at commits

cb49b59fe7 Update to librsvg-2.54.4.
3006d70923 Update to exo-4.16.4.

comment:4 by Douglas R. Reno, 23 months ago

Priority: normalelevated

CVE-2022-32278

CVE-2022-32278

This patch prevents executing possibly malicious .desktop files
from online sources (ftp://, http:// etc.).

See https://gitlab.xfce.org/xfce/exo/-/commit/cc047717c3b5efded2cc7bd419c41a3d1f1e48b6

Note: See TracTickets for help on using tickets.