CVE-2018-18398
Last modified
CVE-2018-18398 is a vulnerability of currently unknown severity. Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could potentially be exploited by an arbitrary local user who creates files in /tmp before the victim uses this input method.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Xfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an out-of-bounds read and SEGV. This could potentially be exploited by an arbitrary local user who creates files in /tmp before the victim uses this input method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xfce | Thunar | < 1.6.15 |
| Xfce | Xfce | < 4.12 |
References
- https://0xd0ff9.wordpress.com/2018/10/18/cve-2018-18398/Exploit, Third Party Advisory
- https://0xd0ff9.wordpress.com/2018/10/18/cve-2018-18398/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-18398?
How severe is CVE-2018-18398?
How do I fix CVE-2018-18398?
Are you affected by CVE-2018-18398?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
