5.8
CVSSv2

CVE-2018-13054

Published: 02/07/2018 Updated: 04/09/2018
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

An issue exists in Cinnamon 1.9.2 up to and including 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 8.0

linuxmint cinnamon

Vendor Advisories

Debian Bug report logs - #903201 cinnamon: CVE-2018-13054: privilege escalation in cinnamon-settings-userspy GUI Package: src:cinnamon; Maintainer for src:cinnamon is Debian Cinnamon Team <debian-cinnamon@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 7 Jul 2018 15:00:02 UTC Sev ...