Bug 1601019 (CVE-2018-14036) - CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_file_authorized_cb() in user.c
Summary: CVE-2018-14036 accountsservice: insufficient path check in user_change_icon_f...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-14036
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 1597495 (view as bug list)
Depends On: 1597499 1601020 1601021 1602918
Blocks: 1601022
TreeView+ depends on / blocked
 
Reported: 2018-07-13 15:19 UTC by Pedro Sampaio
Modified: 2021-10-25 09:46 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-25 09:46:41 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2018-07-13 15:19:48 UTC
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.

Upstream bug:

https://bugs.freedesktop.org/show_bug.cgi?id=107085

Upstream patch:

https://cgit.freedesktop.org/accountsservice/commit/?id=f9abd359f71a5bce421b9ae23432f539a067847a

References:

http://www.openwall.com/lists/oss-security/2018/07/02/2

Comment 1 Pedro Sampaio 2018-07-13 15:20:14 UTC
Created accountsservice tracking bugs for this issue:

Affects: fedora-all [bug 1601020]

Comment 3 Tomas Hoger 2018-07-13 19:17:39 UTC
*** Bug 1597495 has been marked as a duplicate of this bug. ***

Comment 6 Pedro Yóssis Silva Barbosa 2018-07-18 20:07:56 UTC
The vulnerability would trigger an information disclosure (e.g., file read) concern. No vulnerable third party applications were found so far.


Note You need to log in before you can comment on or make changes to this bug.