Vulnerability Description
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xfce | Xfce4-Settings | < 4.16.4 |
| Debian | Debian Linux | 11.0 |
| Fedoraproject | Fedora | 37 |
Related Weaknesses (CWE)
References
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/55e3c5fb667e96ad1412cf24987PatchVendor Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/f34a92a84f96268ad24a7a13fd5PatchVendor Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/issues/390Broken Link
- https://gitlab.xfce.org/xfce/xfce4-settings/-/tagsRelease NotesVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202305-05
- https://www.debian.org/security/2022/dsa-5296Third Party Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/55e3c5fb667e96ad1412cf24987PatchVendor Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/f34a92a84f96268ad24a7a13fd5PatchVendor Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/issues/390Broken Link
- https://gitlab.xfce.org/xfce/xfce4-settings/-/tagsRelease NotesVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202305-05
- https://www.debian.org/security/2022/dsa-5296Third Party Advisory
- https://gitlab.xfce.org/xfce/xfce4-settings/-/issues/390Broken Link
FAQ
What is CVE-2022-45062?
CVE-2022-45062 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
How severe is CVE-2022-45062?
CVE-2022-45062 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-45062?
Check the references section above for vendor advisories and patch information. Affected products include: Xfce Xfce4-Settings, Debian Debian Linux, Fedoraproject Fedora.