Advisories ยป MGASA-2021-0306

Updated thunar packages fix a security vulnerability

Publication date: 30 Jun 2021
Modification date: 30 Jun 2021
Type: security
Affected Mageia releases : 8
CVE: CVE-2021-32563

Description

An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2.
When called with a regular file as a command-line argument, it delegates to
a different program (based on the file type) without user confirmation.
This could be used to achieve code execution (CVE-2021-32563).
                

References

SRPMS

8/core