CVE-2021-32563
Gentoo Linux Security Advisory 202402-20
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.
Se detectó un problema en Thunar versiones anteriores a 4.16.7 y versiones 4.17.x anteriores a 4.17.2. Cuando es llamado con un archivo normal como argumento de línea de comandos, es delegado en un programa diferente (según el tipo de archivo) sin la confirmación del usuario. Esto podría ser usado para lograr una ejecución de código
A vulnerability has been discovered in Thunar which may lead to arbitrary code execution Versions greater than or equal to 4.17.3 are affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-11 CVE Reserved
- 2021-05-11 CVE Published
- 2024-08-03 CVE Updated
- 2025-01-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-913: Improper Control of Dynamically-Managed Code Resources
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2021/05/11/3 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2023/01/05/1 | Mailing List |
|
http://www.openwall.com/lists/oss-security/2023/01/05/2 | Mailing List |
|
https://gitlab.xfce.org/xfce/thunar/-/tags | Release Notes | |
https://www.openwall.com/lists/oss-security/2021/05/09/2 | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xfce Search vendor "Xfce" | Thunar Search vendor "Xfce" for product "Thunar" | < 4.16.7 Search vendor "Xfce" for product "Thunar" and version " < 4.16.7" | - |
Affected
| ||||||
Xfce Search vendor "Xfce" | Thunar Search vendor "Xfce" for product "Thunar" | >= 4.17.0 < 4.17.2 Search vendor "Xfce" for product "Thunar" and version " >= 4.17.0 < 4.17.2" | - |
Affected
|