CVE-2019-17080: High severity linux mint vulnerability
Published Oct 2, 2019
·Updated
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWSCACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
Affected Software
1 affected component
LinuxMint Mintinstall Linux Mint=7.9.9
Event History
Oct 2, 2019
CVE Published
via MITRE·12:17 PM
Data Sourced
via MITRE·12:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17080?
The severity of CVE-2019-17080 is high, with a CVSS score of 7.8.
2
What software versions are affected by CVE-2019-17080?
The affected software version of CVE-2019-17080 is mintinstall 7.9.9.
3
How can CVE-2019-17080 be exploited?
CVE-2019-17080 can be exploited if a REVIEWS_CACHE file is controlled by an attacker, allowing for code execution.
4
How can I fix CVE-2019-17080?
CVE-2019-17080 is resolved in version 8.0.0 and backports, so updating to the latest version of mintinstall will fix the vulnerability.
5
What is the Common Weakness Enumeration (CWE) ID of CVE-2019-17080?
CVE-2019-17080 is associated with CWE-502.