Lucene search

K
ubuntuUbuntuUSN-4844-1
HistoryMar 15, 2021 - 12:00 a.m.

Cinnamon vulnerability

2021-03-1500:00:00
ubuntu.com
24
cinnamon settings users
symlinks
arbitrary files
root
ubuntu 18.04
ubuntu 16.04
esm
vulnerability

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.003

Percentile

70.1%

Releases

  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • cinnamon - Innovative and comfortable desktop

Details

Matthias Gerstner discovered that the cinnamon-settings-users utility in
Cinnamon did not safely handle symlinks. An unprivileged attacker could
potentially use this vulnerability to overwrite arbitrary files as root.

Rows per page:
1-10 of 131

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

AI Score

8

Confidence

High

EPSS

0.003

Percentile

70.1%