Where
-Infinity
0

Vendor Risk Score

See how linux mint compares to other vendors in security performance

View Risk Score →
Severity
9
Command Injection, Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in checkconnection, dropdatareceivedcb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.

First published (updated )
Severity
7.8
Path Traversal
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21897.

1 / 2
Source: MITRE
First published (updated )
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-22132.

1 / 2
Source: MITRE
First published (updated )
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user.

1 / 2
Source: ZDI
First published (updated )
Advisory
ZDI-23-1836
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CBT files. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user.

1 / 2
Source: ZDI
First published (updated )
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.

1 / 2
Source: ZDI
First published (updated )
Advisory
ZDI-23-1835
Severity
7.8
AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPUB files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user.

1 / 2
Source: ZDI
First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
May 3, 2021

End of life: 5/3/2021

First published (updated )
EOL
May 3, 2021

End of life: 5/3/2021

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2025

End of life: 4/30/2025

First published (updated )
EOL
Apr 30, 2025

End of life: 4/30/2025

First published (updated )
EOL
Apr 30, 2025

End of life: 4/30/2025

First published (updated )
EOL
Apr 30, 2025

End of life: 4/30/2025

First published (updated )
EOL
Aug 1, 2022

End of life: 8/1/2022

First published (updated )
EOL
Aug 1, 2022

End of life: 8/1/2022

First published (updated )
EOL
Apr 1, 2021

End of life: 4/1/2021

First published (updated )
EOL
Apr 1, 2021

End of life: 4/1/2021

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Apr 30, 2027

End of life: 4/30/2027

First published (updated )
EOL
Jan 1, 2026

End of life: 1/1/2026

First published (updated )
EOL
Jan 1, 2026

End of life: 1/1/2026

First published (updated )
EOL
Apr 1, 2023

End of life: 4/1/2023

First published (updated )
EOL
Apr 1, 2023

End of life: 4/1/2023

First published (updated )
EOL
Apr 1, 2023

End of life: 4/1/2023

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203