CVE-2018-13054: High severity debian linux vulnerability
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in onfacebrowsemenuitemactivated and onfacemenuitemactivated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-13054?
CVE-2018-13054 is a vulnerability in Cinnamon versions 1.9.2 through 3.8.6 that allows unauthorized users to modify other users' icon files.
What is the severity of CVE-2018-13054?
CVE-2018-13054 has a severity rating of 8.1, which is considered high.
How does CVE-2018-13054 affect Debian Debian Linux?
CVE-2018-13054 affects Debian Debian Linux version 8.0.
How does CVE-2018-13054 affect Linuxmint Cinnamon?
CVE-2018-13054 affects Linuxmint Cinnamon versions 1.9.2 through 3.8.6.
How can I fix CVE-2018-13054?
To fix CVE-2018-13054, upgrade Cinnamon to a version higher than 3.8.6.