UBUNTU-CVE-2021-32563

Source
https://ubuntu.com/security/CVE-2021-32563
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-32563.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-32563
Related
Published
2021-05-11T05:15:00Z
Modified
2025-01-13T10:22:33Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.

References

Affected packages

Ubuntu:Pro:16.04:LTS / thunar

Package

Name
thunar
Purl
pkg:deb/ubuntu/thunar@1.6.11-0ubuntu0.16.04.2?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.10-1
1.6.10-2
1.6.10-2ubuntu1
1.6.11-0ubuntu0.16.04.1
1.6.11-0ubuntu0.16.04.2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / thunar

Package

Name
thunar
Purl
pkg:deb/ubuntu/thunar@1.6.15-0ubuntu1.18.04.1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.12-1
1.6.13-1
1.6.13-2
1.6.14-1
1.6.14-1ubuntu1
1.6.15-0ubuntu1
1.6.15-0ubuntu1.18.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:20.04:LTS / thunar

Package

Name
thunar
Purl
pkg:deb/ubuntu/thunar@1.8.14-0ubuntu1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.8.9-1
1.8.11-1
1.8.12-1
1.8.14-0ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}