PT-2024-26866 · Linux Mint · Mintupload

1337Kid

·

Published

2024-05-19

·

Updated

2024-07-10

·

CVE-2024-36053

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions mintupload versions through 4.2.0
Description The issue is related to service-name mishandling, which leads to command injection via shell metacharacters in functions such as check connection, drop data received cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file to exploit this. The issue enables local attacks and can lead to system compromise.
Recommendations For versions through 4.2.0, patch immediately to prevent system compromise. As a temporary workaround, consider restricting access to the check connection, drop data received cb, and Service.remove functions until a patch is available. Additionally, avoid modifying service names in ~/.linuxmint/mintUpload/services/service files to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-36053

Affected Products

Mintupload