Andhrimnirr/Mintinstall-object-injection

Andhrimnirr/Mintinstall-object-injection

Releases0
Stars1
CVE-2019-17080

CVE History

CVEPublishedCVSS v3CVSS v2
7.8 HIGH6.8 MEDIUM

mintinstall (aka Software Manager) 7.9.9 for Linux Mint allows code execution if a REVIEWS_CACHE file is controlled by an attacker, because an unpickle occurs. This is resolved in 8.0.0 and backports.