USN-3994-1: gnome-desktop vulnerability
It was discovered that gnome-desktop incorrectly confined thumbnailers. If a user were tricked into downloading a malicious image file, a remote attacker could possibly combine this issue with another vulnerability to escape the sandbox and execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3994-1?
The severity of USN-3994-1 is considered high due to the potential for remote code execution.
How do I fix USN-3994-1?
To fix USN-3994-1, update the package 'libgnome-desktop-3-17' to the latest version for your Ubuntu release.
Which versions of Ubuntu are affected by USN-3994-1?
USN-3994-1 affects Ubuntu 19.04, 18.10, and 18.04 with specific versions of 'libgnome-desktop-3-17'.
What can an attacker do by exploiting USN-3994-1?
By exploiting USN-3994-1, an attacker could escape the sandbox and execute arbitrary code on the targeted system.
How was USN-3994-1 discovered?
USN-3994-1 was discovered through the identification of incorrect confinement of thumbnailers in gnome-desktop.