An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-cinnamon | Feb 19, 2019 | Jul 2, 2018 | |
| Suse | — | suse-upgrade-cinnamonsuse-upgrade-cinnamon-gschemassuse-upgrade-cinnamon-gschemas-branding-upstream | Jul 29, 2018 | Jul 2, 2018 |
| Ubuntu | ubuntu-pro-upgrade-cinnamonubuntu-pro-upgrade-cinnamon-common | Mar 22, 2023 | Jul 2, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub