UBUNTU-CVE-2018-20167

Source
https://ubuntu.com/security/CVE-2018-20167
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-20167.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-20167
Related
Published
2018-12-17T05:29:00Z
Modified
2025-06-03T17:32:44Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe "cat README.md" command when \e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers unknown file types to the handleunknownmedia() function, which executes xdg-open against the filename specified in the sequence. The use of xdg-open for all unknown file types allows executable file formats with a registered shared MIME type to be executed. An attacker can achieve remote code execution by introducing an executable file and a plain text file containing the control sequence through a fake software project (e.g., in Git or a tarball). When the control sequence is rendered (such as with cat), the executable file will be run.

References

Affected packages

Ubuntu:Pro:16.04:LTS / terminology

Package

Name
terminology
Purl
pkg:deb/ubuntu/terminology@0.7.0-1+deb8u1build0.16.04.1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.7.0-1
0.7.0-1+deb8u1build0.16.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:18.04:LTS / terminology

Package

Name
terminology
Purl
pkg:deb/ubuntu/terminology@0.9.1-1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.9.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:Pro:20.04:LTS / terminology

Package

Name
terminology
Purl
pkg:deb/ubuntu/terminology@1.6.0-2?arch=source&distro=esm-apps/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.3.2-1build1
1.6.0-2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / terminology

Package

Name
terminology
Purl
pkg:deb/ubuntu/terminology@1.12.1-1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.9.0-2
1.10.0-1
1.11.0-1
1.12.1-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}