PT-2011-1159 · None+1 · Conky+1

Segooon

+1

·

Published

2011-10-13

·

Updated

2024-06-15

·

CVE-2011-3616

CVSS v2.0

6.3

Medium

VectorAV:L/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Conky versions prior to 1.8.1
Description The issue concerns a potential security risk in the Conky package, which could lead to the compromise of data integrity and availability. This can be exploited locally. Specifically, the getSkillname function in the eve module of Conky allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.
Recommendations For Conky versions prior to 1.8.1, update to version 1.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /tmp/.cesf file to minimize the risk of exploitation.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1044
BDU:2015-09424
CVE-2011-3616
OPENSUSE-SU-2024:10093-1

Affected Products

Alt Linux
Conky