Robin Peraglie and Johannes Moritz discovered an argument injection bug in the
xfce4-mime-helper component of xfce4-settings, which can be exploited using the
xdg-open common tool. Since xdg-open is used by multiple standard applications
for opening links, this bug could be exploited by an attacker to run arbitrary
code on an user machine by providing a malicious PDF file with specifically
crafted links.
More Stories
USN-7423-1: GNU binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a...
USN-7406-6: Linux kernel (NVIDIA Tegra IGX) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
USN-7402-4: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This...
lemonldap-ng-2.21.0-1.el9
FEDORA-EPEL-2025-0d5707b1a1 Packages in this update: lemonldap-ng-2.21.0-1.el9 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.fc42
FEDORA-2025-aacd0b82cc Packages in this update: lemonldap-ng-2.21.0-1.fc42 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More
lemonldap-ng-2.21.0-1.fc40
FEDORA-2025-80dfa228e7 Packages in this update: lemonldap-ng-2.21.0-1.fc40 Update description: See https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/ Read More