PT-2020-7602 · Canonical · Ubuntu Ui Toolkit
Olivier Tilloy
+1
·
Published
2020-09-10
·
Updated
2020-09-16
·
CVE-2014-1420
CVSS v3.1
3.8
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ubuntu UI Toolkit versions prior to 1.1.1188+14.10.20140813.4-0ubuntu1
Description
The issue concerns the StateSaver component in Ubuntu UI Toolkit, which serializes data to tmp/ files. This could allow an attacker to expose potentially sensitive data. Additionally, StateSaver opens files without the O EXCL flag, making it possible for an attacker to launch a symlink attack. However, this risk is partially mitigated by Ubuntu's restrictions on symlinks and hardlinks.
Recommendations
For versions prior to 1.1.1188+14.10.20140813.4-0ubuntu1, update to version 1.1.1188+14.10.20140813.4-0ubuntu1 or later to resolve the issue. As a temporary workaround, consider restricting access to the tmp/ files used by StateSaver to minimize the risk of exploitation.
Fix
Deserialization of Untrusted Data
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ubuntu Ui Toolkit