Skip to content

[SRU] Thunar CVE-2021-32563 (focal, groovy, hirsute) #6

@bluesabre

Description

@bluesabre

Describe the bug(s) being fixed
CVE-2021-32563 affects Thunar versions found in supported releases. Related patches:

GitLab issues #121, #575

To Reproduce
Steps to reproduce the behavior:

  1. Execute thunar ~/Pictures/icon.png
  2. The default application loads the file.

Expected behavior
Thunar should instead open, selecting the file.

Desktop (please complete the following information):

  • Xubuntu Releases: focal, groovy, hirsute
  • Package: thunar
  • Versions: 1.8.14-0ubuntu1, 1.8.15-1, 4.16.6-0ubuntu1

Additional context
Scripts and applications depending on the previous functionality will be adversely affected. Since this functionality is specific to Thunar, this change should have minimal regression impact.

Verification

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions