CVE-2018-13054
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
02/07/2018
Last modified:
04/09/2018
Description
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:linuxmint:cinnamon:*:*:*:*:*:*:*:* | 1.9.2 (including) | 3.8.6 (including) |
To consult the complete list of CPE names with products and versions, see this page