CVE-2011-0702

The feh_unique_filename function in utils.c in feh before 1.11.2 might allow local users to overwrite arbitrary files via a symlink attack on a /tmp/feh_ temporary file.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:feh_project:feh:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.4:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.3.5:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.10:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.9:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.8:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.7:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.11:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.6:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.5:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.6.1:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:1.10.1:*:*:*:*:*:*:*
cpe:2.3:a:feh_project:feh:*:*:*:*:*:*:*:*

Information

Published : 2011-02-14 13:00

Updated : 2020-02-27 05:13


NVD link : CVE-2011-0702

Mitre link : CVE-2011-0702


JSON object : View

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')

Advertisement

dedicated server usa

Products Affected

feh_project

  • feh