[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-13054 -- cinnamon

ID: oval:org.secpod.oval:def:2001275Date: (C)2019-04-22   (M)2023-04-27
Class: VULNERABILITYFamily: unix




An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of other users" icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user"s $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.

Platform:
Debian 8.x
Debian 9.x
Product:
cinnamon
Reference:
CVE-2018-13054
CVE    1
CVE-2018-13054
CPE    4
cpe:/o:debian:debian_linux:8.0
cpe:/o:debian:debian_linux:9.x
cpe:/o:debian:debian_linux:8.x
cpe:/a:linuxmint:cinnamon
...

© SecPod Technologies