Bugzilla – Bug 1099266
VUL-0: CVE-2018-12560: cantata: Directory traversal in the D-Bus service of cantata-mounter
Last modified: 2018-06-27 11:09:59 UTC
rh#1595567 An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring. References: https://bugzilla.redhat.com/show_bug.cgi?id=1595567 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12560 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-12560.html
We don't build with this option. *** This bug has been marked as a duplicate of bug 1091824 ***