First published: Mon Jul 02 2018(Updated: )
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Debian Linux | =8.0 | |
Linux Mint Cinnamon | >=1.9.2<=3.8.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13054 is a vulnerability in Cinnamon versions 1.9.2 through 3.8.6 that allows unauthorized users to modify other users' icon files.
CVE-2018-13054 has a severity rating of 8.1, which is considered high.
CVE-2018-13054 affects Debian Debian Linux version 8.0.
CVE-2018-13054 affects Linuxmint Cinnamon versions 1.9.2 through 3.8.6.
To fix CVE-2018-13054, upgrade Cinnamon to a version higher than 3.8.6.