First published: Wed Oct 02 2019(Updated: )
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Linuxmint Mintinstall | =7.9.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-17080 is high, with a CVSS score of 7.8.
The affected software version of CVE-2019-17080 is mintinstall 7.9.9.
CVE-2019-17080 can be exploited if a REVIEWS_CACHE file is controlled by an attacker, allowing for code execution.
CVE-2019-17080 is resolved in version 8.0.0 and backports, so updating to the latest version of mintinstall will fix the vulnerability.
CVE-2019-17080 is associated with CWE-502.