VYPR
Unrated severityNVD Advisory· Published Sep 10, 2020· Updated Sep 16, 2024

Insecure temp file usage in Ubuntu UI toolkit

CVE-2014-1420

Description

On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink restrictions in Ubuntu. Fixed in 1.1.1188+14.10.20140813.4-0ubuntu1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Range: <1.1.1188+14.10.20140813.4-0ubuntu1
  • Canonical/ubuntu-ui-toolkitv5
    Range: 1.1.1188

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.