{ "schema_version": "1.4.0", "id": "GHSA-gvpc-fhpp-hm84", "modified": "2024-04-04T00:03:23Z", "published": "2022-05-24T16:44:07Z", "aliases": [ "CVE-2016-1579" ], "details": "UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run arbitrary commands in an unconfined environment as the phablet user.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2016-1579" }, { "type": "WEB", "url": "https://bazaar.launchpad.net/~phablet-team/ubuntu-download-manager/trunk/revision/359" } ], "database_specific": { "cwe_ids": [], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2019-04-22T16:29:00Z" } }