PT-2011-2822 · Feh · Feh

Publicado

2011-02-14

·

Atualizado

2020-02-27

·

CVE-2011-1031

CVSS v2.0

3.3

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions feh versions 1.11.2 and earlier
Description The issue is related to the feh unique filename function in utils.c, which might allow local users to create arbitrary files via a symlink attack on a /tmp/feh temporary file.
Recommendations For feh versions 1.11.2 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict access to the feh unique filename function in utils.c to minimize the risk of arbitrary file creation.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1031

Produtos afetados

Feh