cbcvebase.
CVE-2017-14604
published 2017-09-20

CVE-2017-14604: GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop…

PriorityP333medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
2.47%
82.9th percentile
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiannautilus< nautilus 3.25.90-1 (bookworm)nautilus 3.25.90-1 (bookworm)
gnomenautilus< 3.23.903.23.90
gnomenautilus>= 0 < 3.25.90-13.25.90-1
gnomenautilus>= 0 < 3.25.90-13.25.90-1
gnomenautilus>= 0 < 3.25.90-13.25.90-1
gnomenautilus>= 0 < 3.25.90-13.25.90-1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.