CVE-2024-36053: Command Injection
In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in checkconnection, dropdatareceivedcb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36053?
CVE-2024-36053 has a medium severity rating due to its potential for command injection vulnerabilities.
How do I fix CVE-2024-36053?
To fix CVE-2024-36053, users should update the mintupload package to version 4.2.1 or later.
What systems are affected by CVE-2024-36053?
CVE-2024-36053 affects the mintupload package through version 4.2.0 on Linux Mint systems.
What kind of exploit is possible with CVE-2024-36053?
CVE-2024-36053 allows for command injection via user-modified service names in specific service files.
Is there a workaround for CVE-2024-36053 while waiting for a patch?
A temporary workaround for CVE-2024-36053 is to avoid using service names that include shell metacharacters.