From the announcement: Release notes for 4.16.4 ======================== (Security Patch) - exo-open : Only execute local .desktop files
Cool. A non-public CVE that you can only find in commit history. https://gitlab.xfce.org/xfce/exo/-/commit/c71c04ff5882b2866a0d8506fb460d4ef796de9f https://gitlab.xfce.org/xfce/exo/-/commit/cc047717c3b5efded2cc7bd419c41a3d1f1e48b6 Thank you for filing!
Cleanup done.
Thanks!
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=5b0117588db95c6646c834b4a4a596b85ff5e937 commit 5b0117588db95c6646c834b4a4a596b85ff5e937 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-09-22 06:39:07 +0000 Commit: Hans de Graaff <graaff@gentoo.org> CommitDate: 2024-09-22 06:39:16 +0000 [ GLSA 202409-09 ] Exo: Arbitrary Code Execution Bug: https://bugs.gentoo.org/851201 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: Hans de Graaff <graaff@gentoo.org> glsa-202409-09.xml | 42 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+)