VDB
CVE-2022-45062
CVE-2022-45062
PUBLISHED
CVSS 9.800000190734863 CRITICAL
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
EPSS 4.02% · 88.7th percentile
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
4.02%
88.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| xfce | xfce4-settings | 0, 4.17.0 |
| fedoraproject | fedora | 37 |
| debian | debian_linux | 11.0 |
Timeline
- Nov 9, 2022 CVE Published
- Nov 9, 2022 EPSS Score
- Dec 22, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- Apr 30, 2023 EPSS Score
- Jun 12, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
- Oct 19, 2023 EPSS Score
- Nov 16, 2023 EPSS Score
- Dec 1, 2023 EPSS Score
- Feb 25, 2024 EPSS Score
References
- https://gitlab.xfce.org/xfce/xfce4-settings/-/issues/390 url
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/55e3c5fb667e96ad1412cf249879262b369d28d7 url
- https://gitlab.xfce.org/xfce/xfce4-settings/-/commit/f34a92a84f96268ad24a7a13fd5edc9f1d526110 url
- https://gitlab.xfce.org/xfce/xfce4-settings/-/tags url
- DSA-5296 vendor-advisory
- FEDORA-2022-7febff96e0 vendor-advisory
- GLSA-202305-05 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-45062 advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGTGTTPFHDUB3EZHVKDK4H32QUUYPPFF url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XGTGTTPFHDUB3EZHVKDK4H32QUUYPPFF url