UBUNTU-CVE-2020-36986

Source
https://ubuntu.com/security/CVE-2020-36986
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36986.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2020-36986
Upstream
  • CVE-2020-36986
Published
2026-01-28T13:15:00Z
Modified
2026-02-04T17:03:15Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Prey 1.9.6 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the CronService to insert malicious code that would execute during application startup or system reboot.

References

Affected packages

Ubuntu:16.04:LTS / prey

Package

Name
prey
Purl
pkg:deb/ubuntu/prey@0.6.2-1.1?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.2-1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "prey",
            "binary_version": "0.6.2-1.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36986.json"

Ubuntu:18.04:LTS / prey

Package

Name
prey
Purl
pkg:deb/ubuntu/prey@0.6.2-1.1?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*
0.6.2-1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "prey",
            "binary_version": "0.6.2-1.1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2020/UBUNTU-CVE-2020-36986.json"