UBUNTU-CVE-2022-37290

Source
https://ubuntu.com/security/CVE-2022-37290
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-37290
Upstream
Downstream
Related
Published
2022-11-14T08:15:00Z
Modified
2026-02-04T03:12:12.481716Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.

References

Affected packages

Ubuntu:16.04:LTS
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.12.7-1ubuntu0.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.10.4-1
1.12.2-1
1.12.3-1
1.12.4-1
1.12.4-2
1.12.6-1
1.12.7-1
1.12.7-1ubuntu0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "gir1.2-caja"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.12.7-1ubuntu0.1",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@2.8.6-2?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.6.7-1
2.8.6-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.8.6-2",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "2.8.6-2",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "2.8.6-2",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "2.8.6-2",
            "binary_name": "nemo"
        },
        {
            "binary_version": "2.8.6-2",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
Ubuntu:18.04:LTS
nautilus

Package

Name
nautilus
Purl
pkg:deb/ubuntu/nautilus@1:3.26.4-0~ubuntu18.04.6?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.26.4-0~ubuntu18.04.6

Affected versions

1:3.*
1:3.26.0-0ubuntu1
1:3.26.2-0ubuntu1
1:3.26.2-0ubuntu3.1
1:3.26.3-0ubuntu1
1:3.26.3-0ubuntu2
1:3.26.3-0ubuntu3
1:3.26.3-0ubuntu4
1:3.26.4-0~ubuntu18.04.1
1:3.26.4-0~ubuntu18.04.2
1:3.26.4-0~ubuntu18.04.3
1:3.26.4-0~ubuntu18.04.4
1:3.26.4-0~ubuntu18.04.5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:3.26.4-0~ubuntu18.04.6",
            "binary_name": "gir1.2-nautilus-3.0"
        },
        {
            "binary_version": "1:3.26.4-0~ubuntu18.04.6",
            "binary_name": "libnautilus-extension-dev"
        },
        {
            "binary_version": "1:3.26.4-0~ubuntu18.04.6",
            "binary_name": "libnautilus-extension1a"
        },
        {
            "binary_version": "1:3.26.4-0~ubuntu18.04.6",
            "binary_name": "nautilus"
        },
        {
            "binary_version": "1:3.26.4-0~ubuntu18.04.6",
            "binary_name": "nautilus-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.20.2-4ubuntu1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.18.4-0ubuntu2
1.18.4-2
1.18.5-1
1.18.5-2
1.19.3-0ubuntu1
1.20.0-0ubuntu1
1.20.0-2
1.20.1-0ubuntu1
1.20.1-1
1.20.2-0ubuntu1
1.20.2-1ubuntu1
1.20.2-3ubuntu1
1.20.2-4ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "gir1.2-caja"
        },
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "gir1.2-caja-2.0"
        },
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.20.2-4ubuntu1",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@3.6.5-1ubuntu1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.7-1ubuntu1
3.6.5-1
3.6.5-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.6.5-1ubuntu1",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "3.6.5-1ubuntu1",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "3.6.5-1ubuntu1",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "3.6.5-1ubuntu1",
            "binary_name": "nemo"
        },
        {
            "binary_version": "3.6.5-1ubuntu1",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
Ubuntu:20.04:LTS
nautilus

Package

Name
nautilus
Purl
pkg:deb/ubuntu/nautilus@1:3.36.3-0ubuntu1.20.04.2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:3.36.3-0ubuntu1.20.04.2

Affected versions

1:3.*
1:3.34.1-1ubuntu1
1:3.35.90-1ubuntu2
1:3.35.92-1ubuntu1
1:3.36.0-1ubuntu1
1:3.36.1-1ubuntu1
1:3.36.1.1-1ubuntu1
1:3.36.1.1-1ubuntu2
1:3.36.2-0ubuntu1
1:3.36.3-0ubuntu1
1:3.36.3-0ubuntu1.20.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:3.36.3-0ubuntu1.20.04.2",
            "binary_name": "gir1.2-nautilus-3.0"
        },
        {
            "binary_version": "1:3.36.3-0ubuntu1.20.04.2",
            "binary_name": "libnautilus-extension-dev"
        },
        {
            "binary_version": "1:3.36.3-0ubuntu1.20.04.2",
            "binary_name": "libnautilus-extension1a"
        },
        {
            "binary_version": "1:3.36.3-0ubuntu1.20.04.2",
            "binary_name": "nautilus"
        },
        {
            "binary_version": "1:3.36.3-0ubuntu1.20.04.2",
            "binary_name": "nautilus-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.24.0-1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.22.2-0ubuntu1
1.22.3-1
1.24.0-0ubuntu1
1.24.0-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.24.0-1",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.24.0-1",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.24.0-1",
            "binary_name": "gir1.2-caja"
        },
        {
            "binary_version": "1.24.0-1",
            "binary_name": "gir1.2-caja-2.0"
        },
        {
            "binary_version": "1.24.0-1",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.24.0-1",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@4.4.2-2ubuntu2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.0.6-1
4.2.3-2
4.4.2-2
4.4.2-2ubuntu1
4.4.2-2ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "4.4.2-2ubuntu2",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "4.4.2-2ubuntu2",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "4.4.2-2ubuntu2",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "4.4.2-2ubuntu2",
            "binary_name": "nemo"
        },
        {
            "binary_version": "4.4.2-2ubuntu2",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
Ubuntu:22.04:LTS
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.26.0-1ubuntu1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.26.0-0ubuntu1
1.26.0-1ubuntu1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.26.0-1ubuntu1",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.26.0-1ubuntu1",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.26.0-1ubuntu1",
            "binary_name": "gir1.2-caja-2.0"
        },
        {
            "binary_version": "1.26.0-1ubuntu1",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.26.0-1ubuntu1",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nautilus

Package

Name
nautilus
Purl
pkg:deb/ubuntu/nautilus@1:42.2-0ubuntu2.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:42.2-0ubuntu2.1

Affected versions

1:40.*
1:40.2-1ubuntu1
1:41.*
1:41.1-1ubuntu1
1:41.2-1ubuntu1
Other
1:42~beta-1ubuntu1
1:42~rc-1ubuntu1
1:42.*
1:42.0-1ubuntu2
1:42.1.1-0ubuntu1
1:42.2-0ubuntu1
1:42.2-0ubuntu2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "1:42.2-0ubuntu2.1",
            "binary_name": "gir1.2-nautilus-3.0"
        },
        {
            "binary_version": "1:42.2-0ubuntu2.1",
            "binary_name": "libnautilus-extension-dev"
        },
        {
            "binary_version": "1:42.2-0ubuntu2.1",
            "binary_name": "libnautilus-extension1a"
        },
        {
            "binary_version": "1:42.2-0ubuntu2.1",
            "binary_name": "nautilus"
        },
        {
            "binary_version": "1:42.2-0ubuntu2.1",
            "binary_name": "nautilus-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@5.2.4-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.8.6-2
5.*
5.0.5-1
5.2.2-1
5.2.4-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "5.2.4-1",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "5.2.4-1",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "5.2.4-1",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "5.2.4-1",
            "binary_name": "nemo"
        },
        {
            "binary_version": "5.2.4-1",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
Ubuntu:24.04:LTS
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.26.3-1build3?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.26.1-1
1.26.3-1
1.26.3-1build1
1.26.3-1build2
1.26.3-1build3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.26.3-1build3",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.26.3-1build3",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.26.3-1build3",
            "binary_name": "gir1.2-caja-2.0"
        },
        {
            "binary_version": "1.26.3-1build3",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.26.3-1build3",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@6.0.2-1ubuntu2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.8.4-1
5.8.5-2
6.*
6.0.2-1ubuntu1
6.0.2-1ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.0.2-1ubuntu2",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "6.0.2-1ubuntu2",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "6.0.2-1ubuntu2",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "6.0.2-1ubuntu2",
            "binary_name": "nemo"
        },
        {
            "binary_version": "6.0.2-1ubuntu2",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
Ubuntu:25.10
caja

Package

Name
caja
Purl
pkg:deb/ubuntu/caja@1.26.4-1build1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.26.3-1build3
1.26.4-1
1.26.4-1build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.26.4-1build1",
            "binary_name": "caja"
        },
        {
            "binary_version": "1.26.4-1build1",
            "binary_name": "caja-common"
        },
        {
            "binary_version": "1.26.4-1build1",
            "binary_name": "gir1.2-caja-2.0"
        },
        {
            "binary_version": "1.26.4-1build1",
            "binary_name": "libcaja-extension-dev"
        },
        {
            "binary_version": "1.26.4-1build1",
            "binary_name": "libcaja-extension1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"
nemo

Package

Name
nemo
Purl
pkg:deb/ubuntu/nemo@6.4.5-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.5-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "6.4.5-1",
            "binary_name": "gir1.2-nemo-3.0"
        },
        {
            "binary_version": "6.4.5-1",
            "binary_name": "libnemo-extension-dev"
        },
        {
            "binary_version": "6.4.5-1",
            "binary_name": "libnemo-extension1"
        },
        {
            "binary_version": "6.4.5-1",
            "binary_name": "nemo"
        },
        {
            "binary_version": "6.4.5-1",
            "binary_name": "nemo-data"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-37290.json"