Stack-based buffer overflow in the Panel (xfce4-panel) component in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via Launcher tooltips. NOTE: a second buffer overflow (over-read) in the xfce_mkdirhier function was also reported, but it might not be exploitable for a crash or code execution, so it is not a vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xfce4-panel | Jul 30, 2024 | Jan 9, 2008 |
| Freebsd | — | Upgrade xfce4-panelUpgrade libxfce4gui | Dec 10, 2025 | Jan 22, 2008 |
| Gentoo Linux | — | Upgrade xfce-base/xfce4-panel.Upgrade xfce-base/libxfcegui4. | Oct 30, 2017 | Jan 9, 2008 |
| Suse | — | Upgrade xfce4-panelUpgrade xfce4-panel-devel | Dec 12, 2013 | Jan 9, 2008 |
| Ubuntu | — | Upgrade xfce4-panel | Nov 19, 2024 | Jan 9, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub