USN-4844-1: Cinnamon vulnerability
15 March 2021
Cinnamon could be made to overwrite files as root.
Releases
Packages
- cinnamon - Innovative and comfortable desktop
Details
Matthias Gerstner discovered that the cinnamon-settings-users utility in
Cinnamon did not safely handle symlinks. An unprivileged attacker could
potentially use this vulnerability to overwrite arbitrary files as root.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
cinnamon-common
-
3.6.7-8ubuntu1+esm1
Available with Ubuntu Pro
-
cinnamon
-
3.6.7-8ubuntu1+esm1
Available with Ubuntu Pro
Ubuntu 16.04
-
cinnamon-common
-
2.8.6-1ubuntu1+esm1
Available with Ubuntu Pro
-
cinnamon
-
2.8.6-1ubuntu1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.