CVE-2018-14036
published 2018-07-13CVE-2018-14036: Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb()…
PriorityP434medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
3.09%
86.2th percentile
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | accountsservice | >= 0 < 0.6.45-2 | 0.6.45-2 |
| canonical | accountsservice | >= 0 < 0.6.45-2 | 0.6.45-2 |
| canonical | accountsservice | >= 0 < 0.6.45-2 | 0.6.45-2 |
| canonical | accountsservice | >= 0 < 0.6.45-2 | 0.6.45-2 |
| canonical | accountsservice | >= 0 < 0.6.40-2ubuntu11.6 | 0.6.40-2ubuntu11.6 |
| canonical | accountsservice | >= 0 < 0.6.45-1ubuntu1.3 | 0.6.45-1ubuntu1.3 |
| canonical | accountsservice | >= 0 < 0.6.55-0ubuntu12~20.04.4 | 0.6.55-0ubuntu12~20.04.4 |
| canonical | accountsservice | >= 0 < 0.6.35-0ubuntu7.3+esm2 | 0.6.35-0ubuntu7.3+esm2 |
| debian | accountsservice | < accountsservice 0.6.45-2 (bookworm) | accountsservice 0.6.45-2 (bookworm) |
| freedesktop | accountsservice | < 0.6.50 | 0.6.50 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2pjf-fjvv-2rf2: Directory Traversal with
ghsa_unreviewed·2022-05-14
CVE-2018-14036 [MEDIUM] CWE-22 GHSA-2pjf-fjvv-2rf2: Directory Traversal with
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
OSV
accountsservice vulnerabilities
osv·2020-11-04·CVSS 6.5
CVE-2020-16126 [MEDIUM] accountsservice vulnerabilities
accountsservice vulnerabilities
USN-4616-1 fixed several vulnerabilities in AccountsService. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Kevin Backhouse discovered that AccountsService incorrectly dropped
privileges. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service.
(CVE-2020-16126)
Matthias Gerstner discovered that AccountsService incorrectly handled
certain path checks. A local attacker could possibly use this issue to
read arbitrary files. (CVE-2018-14036)
OSV
accountsservice vulnerabilities
osv·2020-11-03·CVSS 6.5
CVE-2020-16126 [MEDIUM] accountsservice vulnerabilities
accountsservice vulnerabilities
Kevin Backhouse discovered that AccountsService incorrectly dropped
privileges. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service.
(CVE-2020-16126)
Kevin Backhouse discovered that AccountsService incorrectly handled reading
.pam_environment files. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-16127)
Matthias Gerstner discovered that AccountsService incorrectly handled
certain path checks. A local attacker could possibly use this issue to
read arbitrary files. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-14036)
OSV
CVE-2018-14036: Directory Traversal with
osv·2018-07-13·CVSS 6.5
CVE-2018-14036 [MEDIUM] CVE-2018-14036: Directory Traversal with
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Ubuntu
AccountsService vulnerabilities
vendor_ubuntu·2020-11-04·CVSS 6.5
CVE-2020-16126 [MEDIUM] AccountsService vulnerabilities
Title: AccountsService vulnerabilities
Summary: Several security issues were fixed in AccountsService.
USN-4616-1 fixed several vulnerabilities in AccountsService. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Kevin Backhouse discovered that AccountsService incorrectly dropped
privileges. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service.
(CVE-2020-16126)
Matthias Gerstner discovered that AccountsService incorrectly handled
certain path checks. A local attacker could possibly use this issue to
read arbitrary files. (CVE-2018-14036)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Ubuntu
AccountsService vulnerabilities
vendor_ubuntu·2020-11-03·CVSS 6.5
CVE-2020-16126 [MEDIUM] AccountsService vulnerabilities
Title: AccountsService vulnerabilities
Summary: Several security issues were fixed in AccountsService.
Kevin Backhouse discovered that AccountsService incorrectly dropped
privileges. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service.
(CVE-2020-16126)
Kevin Backhouse discovered that AccountsService incorrectly handled reading
.pam_environment files. A local user could possibly use this issue to cause
AccountsService to crash or hang, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-16127)
Matthias Gerstner discovered that AccountsService incorrectly handled
certain path checks. A local attacker could possibly use this issue to
read arbitrary files. This issue only
Red Hat
accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
vendor_redhat·2018-07-13·CVSS 6.5
CVE-2018-14036 [MEDIUM] CWE-22 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Package: accountsservice (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-14036: accountsservice - Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 b...
vendor_debian·2018·CVSS 6.5
CVE-2018-14036 [MEDIUM] CVE-2018-14036: accountsservice - Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 b...
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Scope: local
bookworm: resolved (fixed in 0.6.45-2)
bullseye: resolved (fixed in 0.6.45-2)
forky: resolved (fixed in 0.6.45-2)
sid: resolved (fixed in 0.6.45-2)
trixie: resolved (fixed in 0.6.45-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c [fedora-all]
bugzilla·2018-07-13·CVSS 6.5
CVE-2018-14036 [MEDIUM] CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c [fedora-all]
CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
bugzilla·2018-07-13·CVSS 6.5
CVE-2018-14036 [MEDIUM] CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Upstream bug:
https://bugs.freedesktop.org/show_bug.cgi?id=107085
Upstream patch:
https://cgit.freedesktop.org/accountsservice/commit/?id=f9abd359f71a5bce421b9ae23432f539a067847a
References:
http://www.openwall.com/lists/oss-security/2018/07/02/2
Discussion:
Created accountsservice tracking bugs for this issue:
Affects: fedora-all [bug 1601020]
---
*** Bug 1597495 has been marked as a duplicate of this bug. ***
---
The vulnerability would trigger an information disclosure (e.g., file read) concern. No vul
http://www.openwall.com/lists/oss-security/2018/07/02/2http://www.securityfocus.com/bid/104757https://bugs.freedesktop.org/show_bug.cgi?id=107085https://bugzilla.suse.com/show_bug.cgi?id=1099699https://cgit.freedesktop.org/accountsservice/commit/?id=f9abd359f71a5bce421b9ae23432f539a067847ahttp://www.openwall.com/lists/oss-security/2018/07/02/2http://www.securityfocus.com/bid/104757https://bugs.freedesktop.org/show_bug.cgi?id=107085https://bugzilla.suse.com/show_bug.cgi?id=1099699https://cgit.freedesktop.org/accountsservice/commit/?id=f9abd359f71a5bce421b9ae23432f539a067847a
2018-07-13
Published