HIGH
An issue was discovered in Cinnamon 1.9.2 through 3.8.6
Published Jul 2, 2018
8.1
HIGHCVSS 3.0
EPSS 2.20%
Description
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Affected products
No data.
Configuration 1
- 8.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://bugzilla.suse.com/show_bug.cgi?id=1083067 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/linuxmint/Cinnamon/pull/7683 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1083067 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/linuxmint/Cinnamon/pull/7683 | x_refsource_MISCPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2018/07/msg00011.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 2, 2018
Updated Aug 5, 2024
Reserved Jul 2, 2018
Link CVE-2018-13054
CISA Vulnrichment
Updated n/a