Debian Security Advisory

DLA-1420-1 cinnamon -- LTS security update

Date Reported:
13 Jul 2018
Affected Packages:
cinnamon
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-13054.
More information:

It was discovered that there was a symlink attack in the Cinnamon desktop environment.

An attacker could overwrite an arbitrary file on the filesystem via a $HOME/.face icon file (as the cinnamon-settings-users.py GUI runs as root).

For Debian 8 Jessie, this issue has been fixed in cinnamon version 2.2.16-5+deb8u1.

We recommend that you upgrade your cinnamon packages.