CVE-2017-14604 – nautilus: Insufficient validation of trust of .desktop files with execute permission
https://notcve.org/view.php?id=CVE-2017-14604
GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file actually has the potentially unsafe .desktop extension; instead, the UI only shows the .pdf extension. One (slightly) mitigating factor is that an attack requires the .desktop file to have execute permission. The solution is to ask the user to confirm that the file is supposed to be treated as a .desktop file, and then remember the user's answer in the metadata::trusted field. GNOME Nautilus en versiones anteriores a la 3.23.90 permite que los atacantes suplanten un tipo de archivo mediante la extensión de archivo .desktop, tal y como se ve en un ataque en el cual el nombre de un archivo .desktop acaba en .pdf, pero el campo Exec de este archivo lanza un comando "sh-c" malicioso. • http://www.debian.org/security/2017/dsa-3994 http://www.securityfocus.com/bid/101012 https://access.redhat.com/errata/RHSA-2018:0223 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=860268 https://bugzilla.gnome.org/show_bug.cgi?id=777991 https://github.com/GNOME/nautilus/commit/1630f53481f445ada0a455e9979236d31a8d3bb0 https://github.com/GNOME/nautilus/commit/bc919205bf774f6af3fa7154506c46039af5a69b https://github.com/freedomofpress/securedrop/issues/2238 https://micahflee.com/2017/04/breaking-the-secur • CWE-20: Improper Input Validation CWE-345: Insufficient Verification of Data Authenticity •
CVE-2002-0157
https://notcve.org/view.php?id=CVE-2002-0157
Nautilus 1.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the .nautilus-metafile.xml metadata file. Nautilus 1.0.4 y anteriores permiten a usuarios sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos en el fichero .nautilus-metafile.xml • http://online.securityfocus.com/archive/1/270691/2002-04-29/2002-05-05/0 http://www.iss.net/security_center/static/8995.php http://www.redhat.com/support/errata/RHSA-2002-064.html http://www.securityfocus.com/bid/4373 •