CVE-2021-32563
Summary
| CVE | CVE-2021-32563 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-11 05:15:00 UTC |
| Updated | 2023-02-28 19:00:00 UTC |
| Description | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution. |
Risk And Classification
Problem Types: CWE-913
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dont execute files, passed via command line due to security risks (9165a61f) · Commits · Xfce / thunar · GitLab | MISC | gitlab.xfce.org | |
| Regression: Activating Desktop Icon does not Use Default Application (3b54d9d7) · Commits · Xfce / thunar · GitLab | MISC | gitlab.xfce.org | |
| oss-security - Code execution through Thunar | MISC | www.openwall.com | |
| oss-security - Re: Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations | MLIST | www.openwall.com | |
| oss-security - Re: Code execution through Thunar | MLIST | www.openwall.com | |
| Dont execute files, passed via command line due to security risks (1b85b96e) · Commits · Xfce / thunar · GitLab | MISC | gitlab.xfce.org | |
| oss-security - Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations | MLIST | www.openwall.com | |
| Tags · Xfce / thunar · GitLab | MISC | gitlab.xfce.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.