Robin Peraglie and Johannes Moritz discovered that xfce4-settings incorrectly parsed quoted input when processed through xdg-open. A remote attacker could possibly use this issue to inject arbitrary arguments into the default browser or file manager.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "4.16.2-1ubuntu2.22.04.1", "binary_name": "xfce4-helpers" }, { "binary_version": "4.16.2-1ubuntu2.22.04.1", "binary_name": "xfce4-settings" }, { "binary_version": "4.16.2-1ubuntu2.22.04.1", "binary_name": "xfce4-settings-dbgsym" } ] }