Candidate: CVE-2018-12560 PublicDate: 2018-06-19 05:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12560 http://www.openwall.com/lists/oss-security/2018/06/18/1 Description: An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. Arbitrary unmounts can be performed by regular users via directory traversal sequences such as a home/../sys/kernel substring. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=901798 Priority: high Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_cantata: upstream_cantata: released (2.3.0.ds1-2) precise/esm_cantata: DNE trusty_cantata: ignored (reached end-of-life) trusty/esm_cantata: DNE (trusty was needs-triage) xenial_cantata: not-affected (vulnerable code not built) artful_cantata: ignored (reached end-of-life) bionic_cantata: not-affected (vulnerable code not built) cosmic_cantata: not-affected (2.3.0.ds1-2) disco_cantata: not-affected (2.3.0.ds1-2) eoan_cantata: not-affected (2.3.0.ds1-2) devel_cantata: not-affected (2.3.0.ds1-2)