Wind River Support Network

HomeDefectsLIN10-4894
Not to be fixed

LIN10-4894 : Security Advisory - thunar - CVE-2018-18398

Created: Oct 30, 2018    Updated: Dec 22, 2022
Resolved Date: Dec 22, 2022
Found In Version: 10.17.41.1
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could potentially be exploited by an arbitrary local user who creates files in /tmp before the victim uses this input method.

https://nvd.nist.gov/vuln/detail/CVE-2018-18398

CVEs


Live chat
Online