Loading
Generated remediation guidance and an executive summary. No account required.
Directory Traversal with ../ sequences occurs in AccountsService before 0.6.50 because of an insufficient path check in user_change_icon_file_authorized_cb() in user.c.
Use CWE-22, Freedesktop vendor hub and Accountsservice product page to widen CVE-2018-14036 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-16126 and CVE-2020-16127 for nearby disclosures in the same product family.