CVE-2018-14036: Path Traversal
Published Jul 13, 2018
·Updated
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in userchangeiconfileauthorizedcb() in user.c.
Affected Software
1 affected component
Freedesktop accountsservice<0.6.50
Remediation
Event History
Jul 13, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-14036.
2
What is the title of this vulnerability?
The title of this vulnerability is 'Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.'
3
What is the severity of CVE-2018-14036?
The severity of CVE-2018-14036 is medium with a severity value of 6.5.
4
Which software is affected by CVE-2018-14036?
The Freedesktop Accountsservice software version up to exclusive version 0.6.50 is affected by CVE-2018-14036.
5
How can I fix CVE-2018-14036?
To fix CVE-2018-14036, update the AccountsService software to version 0.6.50 or later.