PT-2011-2822 · Feh · Feh

Published

2011-02-14

·

Updated

2020-02-27

·

CVE-2011-1031

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions feh versions 1.11.2 and earlier
Description The issue is related to the feh unique filename function in utils.c, which might allow local users to create arbitrary files via a symlink attack on a /tmp/feh temporary file.
Recommendations For feh versions 1.11.2 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict access to the feh unique filename function in utils.c to minimize the risk of arbitrary file creation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1031

Affected Products

Feh