First published: Mon May 27 2019(Updated: )
It was discovered that gnome-desktop incorrectly confined thumbnailers. If a user were tricked into downloading a malicious image file, a remote attacker could possibly combine this issue with another vulnerability to escape the sandbox and execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libgnome-desktop-3-17 | <3.32.1-1ubuntu1.1 | 3.32.1-1ubuntu1.1 |
Ubuntu | =19.04 | |
All of | ||
ubuntu/libgnome-desktop-3-17 | <3.30.1-1ubuntu1.1 | 3.30.1-1ubuntu1.1 |
Ubuntu | =18.10 | |
All of | ||
ubuntu/libgnome-desktop-3-17 | <3.28.2-0ubuntu1.3 | 3.28.2-0ubuntu1.3 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3994-1 is considered high due to the potential for remote code execution.
To fix USN-3994-1, update the package 'libgnome-desktop-3-17' to the latest version for your Ubuntu release.
USN-3994-1 affects Ubuntu 19.04, 18.10, and 18.04 with specific versions of 'libgnome-desktop-3-17'.
By exploiting USN-3994-1, an attacker could escape the sandbox and execute arbitrary code on the targeted system.
USN-3994-1 was discovered through the identification of incorrect confinement of thumbnailers in gnome-desktop.