VYPR
High severity8.8OSV Advisory· Published Jun 19, 2018· Updated Jun 17, 2026

CVE-2018-12559

CVE-2018-12559

Description

An issue was discovered in the cantata-mounter D-Bus service in Cantata through 2.3.1. The mount target path check in mounter.cpp mpOk() is insufficient. A regular user can consequently mount a CIFS filesystem anywhere (e.g., outside of the /home directory tree) by passing directory traversal sequences such as a home/../usr substring.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Craig Drummond/CantataOSV2 versions
    v2.1.0, v2.2.0, v2.3.0, …+ 1 more
    • (no CPE)range: v2.1.0, v2.2.0, v2.3.0, …
    • (no CPE)range: <=2.3.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.