packetstormsecurity.com
http://packetstormsecurity.com/files/154722/mintinstall-7.9.9-Code-Execution.html CVE-2019-17080
HIGH
mintinstall 7.9.9 - Code Execution
Record summary
CVE-2019-17080 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBmintinstall 7.9.9 - Code ExecutionExploitDB exploitby İbrahim Hakan ŞekerNot analyzed1 file
References
5forums.linuxmint.com
https://forums.linuxmint.com/viewtopic.php?f=143&t=302960 github.com
https://github.com/Andhrimnirr/Mintinstall-object-injection github.com
https://github.com/linuxmint/mintinstall/blob/master/debian/changelog nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-17080