CVE-2018-14036
Summary
| CVE | CVE-2018-14036 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-07-13 12:29:00 UTC |
| Updated | 2018-09-06 16:16:00 UTC |
| Description | Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 107085 – accountsservice: insufficient path check in user_change_icon_file_authorized_cb() |
MISC |
bugs.freedesktop.org |
Exploit, Third Party Advisory |
| oss-security - accountsservice: insufficient path check in
user_change_icon_file_authorized_cb() |
MISC |
www.openwall.com |
Exploit, Mailing List, Third Party Advisory |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| accountsservice - D-Bus interface for user account query and manipulation (mirrored from https://gitlab.freedesktop.org/accountsservice/accountsservice) |
MISC |
cgit.freedesktop.org |
Patch, Third Party Advisory |
| Bug 1099699 – VUL-1: accountsservice: insufficient path check in user_change_icon_file_authorized_cb() |
MISC |
bugzilla.suse.com |
Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 690168 Free Berkeley Software Distribution (FreeBSD) Security Update for accountservice (75aae50b-9e3c-11eb-9bc3-8c164582fbac)