PT-2020-7602 · Canonical · Ubuntu Ui Toolkit

Olivier Tilloy

+1

·

Published

2020-09-10

·

Updated

2020-09-16

·

CVE-2014-1420

CVSS v3.1

3.8

Low

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ubuntu UI Toolkit versions prior to 1.1.1188+14.10.20140813.4-0ubuntu1
Description The issue concerns the StateSaver component in Ubuntu UI Toolkit, which serializes data to tmp/ files. This could allow an attacker to expose potentially sensitive data. Additionally, StateSaver opens files without the O EXCL flag, making it possible for an attacker to launch a symlink attack. However, this risk is partially mitigated by Ubuntu's restrictions on symlinks and hardlinks.
Recommendations For versions prior to 1.1.1188+14.10.20140813.4-0ubuntu1, update to version 1.1.1188+14.10.20140813.4-0ubuntu1 or later to resolve the issue. As a temporary workaround, consider restricting access to the tmp/ files used by StateSaver to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1420

Affected Products

Ubuntu Ui Toolkit