Bug 2539380 - CVE-2026-79079 xiphos: Xiphos: Arbitrary code execution via URL handling and menu popup components [fedora-all]
Summary: CVE-2026-79079 xiphos: Xiphos: Arbitrary code execution via URL handling and ...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: xiphos
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: greg.hellings
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["6a5d2503-cd03-44a1-ac0c-b...
Depends On:
Blocks: CVE-2026-79079
TreeView+ depends on / blocked
 
Reported: 2026-09-23 12:04 UTC by Vladimir Vasilev
Modified: 2026-09-28 05:19 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-23 12:04:20 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

Comment 1 Aaron Rainbolt 2026-09-25 01:32:26 UTC
I'll look into fixing this issue this Saturday if no one beats me to it.

Comment 2 greg.hellings 2026-09-25 01:42:03 UTC
I'm fairly sure this is already fixed in 4.4.0. Several such fixes for "bugs" were in that release, which I already packaged for Rawhide. So it should just be as simple as pulling that into the desired release branch. As I don't have a desktop Fedora install anymore I can't very well test those builds so I refrain from pulling new releases into existing Fedora versions.

But a merge from rawhide with a build and Bodhi fix ought to accomplish what you need.

Comment 3 Aaron Rainbolt 2026-09-25 05:00:30 UTC
I'm a little rusty on what Fedora's policies are around pulling new versions into existing releases (most of my work is in Debian/Ubuntu where the process is "backport the patch", but I know Fedora operates somewhat differently). That sounds like it will probably work though. Thanks for the tip!

Comment 4 Aaron Rainbolt 2026-09-28 05:19:14 UTC
I embarrassingly forgot this over the weekend. I've gotten a packaging VM set up again, I'll try to remember to do this Monday morning.


Note You need to log in before you can comment on or make changes to this bug.