PT-2011-2822 · Feh · Feh
Published
2011-02-14
·
Updated
2020-02-27
·
CVE-2011-1031
CVSS v2.0
3.3
Low
| Vector | AV:L/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
feh versions 1.11.2 and earlier
Description
The issue is related to the
feh unique filename function in utils.c, which might allow local users to create arbitrary files via a symlink attack on a /tmp/feh temporary file.Recommendations
For feh versions 1.11.2 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict access to the
feh unique filename function in utils.c to minimize the risk of arbitrary file creation.Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Feh