Bugzilla – Bug 1099265
VUL-0: CVE-2018-12559: cantata: Directory traversal due to insufficient mount target check in mounter.cpp
Last modified: 2018-06-27 11:11:44 UTC
rh#1595566 An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp `mpOk()` is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequences such as a home/../usr substring. References: https://bugzilla.redhat.com/show_bug.cgi?id=1595566 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12559 http://www.openwall.com/lists/oss-security/2018/06/18/1 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-12559.html https://github.com/CDrummond/cantata/commit/afc4f8315d3e96574925fb530a7004cc9e6ce3d3
We don't build with this option. *** This bug has been marked as a duplicate of bug 1091824 ***