CVE-2018-13054
published 2018-07-02CVE-2018-13054: An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users'…
PriorityP342high8.1CVSS 3.0
AVNACLPRNUIRSUCNIHAH
EPSS
2.20%
80.5th percentile
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cinnamon | < cinnamon 3.8.8-1 (bookworm) | cinnamon 3.8.8-1 (bookworm) |
| debian | debian_linux | — | — |
| linuxmint | cinnamon | >= 0 < 3.8.8-1 | 3.8.8-1 |
| linuxmint | cinnamon | >= 0 < 3.8.8-1 | 3.8.8-1 |
| linuxmint | cinnamon | >= 0 < 3.8.8-1 | 3.8.8-1 |
| linuxmint | cinnamon | >= 0 < 3.8.8-1 | 3.8.8-1 |
| linuxmint | cinnamon | 1.9.2 – 3.8.6 | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6g5m-97v8-hh8j: An issue was discovered in Cinnamon 1
ghsa_unreviewed·2022-05-14
CVE-2018-13054 [HIGH] CWE-59 GHSA-6g5m-97v8-hh8j: An issue was discovered in Cinnamon 1
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
OSV
CVE-2018-13054: An issue was discovered in Cinnamon 1
osv·2018-07-02·CVSS 8.1
CVE-2018-13054 [HIGH] CVE-2018-13054: An issue was discovered in Cinnamon 1
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Ubuntu
Cinnamon vulnerability
vendor_ubuntu·2021-03-15
CVE-2018-13054 Cinnamon vulnerability
Title: Cinnamon vulnerability
Summary: Cinnamon could be made to overwrite files as root.
Matthias Gerstner discovered that the cinnamon-settings-users utility in
Cinnamon did not safely handle symlinks. An unprivileged attacker could
potentially use this vulnerability to overwrite arbitrary files as root.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2018-13054: cinnamon - An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-u...
vendor_debian·2018·CVSS 8.1
CVE-2018-13054 [HIGH] CVE-2018-13054: cinnamon - An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-u...
An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
Scope: local
bookworm: resolved (fixed in 3.8.8-1)
bullseye: resolved (fixed in 3.8.8-1)
forky: resolved (fixed in 3.8.8-1)
sid: resolved (fixed in 3.8.8-1)
trixie: resolved (fixed in 3.8.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI
bugzilla·2018-07-05·CVSS 8.1
CVE-2018-13054 [HIGH] CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI
A flaw was found in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon files are written to the respective user's $HOME/.face location. If an unprivileged user prepares a symlink pointing to an arbitrary location, then this location will be overwritten with the icon content.
References:
https://bugzilla.suse.com/show_bug.cgi?id=1083067
Patch:
https://github.com/linuxmint/Cinnamon/pull/7683
Discussion:
Created cinnamon tracking bugs for this issue:
Affects: epel-7 [bug 1598495]
Affects: fedora-all [bug 1598494]
---
This CVE Bugzill
Bugzilla
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [fedora-all]
bugzilla·2018-07-05·CVSS 8.1
CVE-2018-13054 [HIGH] CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [fedora-all]
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [epel-7]
bugzilla·2018-07-05·CVSS 8.1
CVE-2018-13054 [HIGH] CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [epel-7]
CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to fo
https://bugzilla.suse.com/show_bug.cgi?id=1083067https://github.com/linuxmint/Cinnamon/pull/7683https://lists.debian.org/debian-lts-announce/2018/07/msg00011.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1083067https://github.com/linuxmint/Cinnamon/pull/7683https://lists.debian.org/debian-lts-announce/2018/07/msg00011.html
2018-07-02
Published