ALT-PU-2021-1810-1
Closed vulnerabilities
Published: 2015-10-23
BDU:2021-04682
Уязвимость файлового менеджера Thunar, связанная с неправильным контролем доступа, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2021-05-11
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-32563
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- [oss-security] 20210511 Re: Code execution through Thunar
- [oss-security] 20210511 Re: Code execution through Thunar
- [oss-security] 20230104 Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations
- [oss-security] 20230104 Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations
- [oss-security] 20230105 Re: Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations
- [oss-security] 20230105 Re: Code execution through MIME-type association of Mono interpreter and security expectations of MIME type associations
- https://gitlab.xfce.org/xfce/thunar/-/commit/1b85b96ebf7cb9bf6a3ddf1acee7643643fdf92d
- https://gitlab.xfce.org/xfce/thunar/-/commit/1b85b96ebf7cb9bf6a3ddf1acee7643643fdf92d
- https://gitlab.xfce.org/xfce/thunar/-/commit/3b54d9d7dbd7fd16235e2141c43a7f18718f5664
- https://gitlab.xfce.org/xfce/thunar/-/commit/3b54d9d7dbd7fd16235e2141c43a7f18718f5664
- https://gitlab.xfce.org/xfce/thunar/-/commit/9165a61f95e43cc0b5abf9b98eee2818a0191e0b
- https://gitlab.xfce.org/xfce/thunar/-/commit/9165a61f95e43cc0b5abf9b98eee2818a0191e0b
- https://gitlab.xfce.org/xfce/thunar/-/tags
- https://gitlab.xfce.org/xfce/thunar/-/tags
- https://www.openwall.com/lists/oss-security/2021/05/09/2
- https://www.openwall.com/lists/oss-security/2021/05/09/2