Directory Traversal Vulnerability in AccountsService by FreeDesktop
CVE-2018-14036
6.5MEDIUM
What is CVE-2018-14036?
A directory traversal vulnerability in AccountsService allows attackers to access unauthorized files on the server. This flaw arises from inadequate path checks within the user_change_icon_file_authorized_cb() function in user.c, enabling attackers to manipulate file paths using '../' sequences. The issue affects versions prior to 0.6.50, potentially exposing sensitive information and compromising system integrity.
