XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
| Software | From | Fixed in |
|---|---|---|
| xfce / exo | 4.17.0 | 4.17.2 |
| xfce / exo | - | 4.16.4 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| debian / debian_linux | 11.0 | 11.0.x |