Ubuntu Security Notice 6141-1 - Robin Peraglie and Johannes Moritz discovered that xfce4-settings incorrectly parsed quoted input when processed through xdg-open. A remote attacker could possibly use this issue to inject arbitrary arguments into the default browser or file manager.
2f043764bc68fb396b2e0122391243701d80409155bba15c5060fdb94c8b99b6
Gentoo Linux Security Advisory 202305-5 - A vulnerability has been discovered in xfce4-settings which could result in universal cross site scripting (uXSS). Versions less than 4.17.1 are affected.
fd1ac35c491ad1ad25a93321306d39c2c2d99d312563570dd3a94cb667f35df0
Debian Linux Security Advisory 5296-1 - Robin Peraglie and Johannes Moritz discovered an argument injection bug in the xfce4-mime-helper component of xfce4-settings, which can be exploited using the xdg-open common tool. Since xdg-open is used by multiple standard applications for opening links, this bug could be exploited by an attacker to run arbitrary code on an user machine by providing a malicious PDF file with specifically crafted links.
5313fb47906b2d901e10c9452bdc90cb3b55ceae32efa216ba1a94c0076fec3a