PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).
References
Link | Resource |
---|---|
https://git.lxde.org/gitweb/?p=lxde/pcmanfm.git;a=commit;h=bc8c3d871e9ecc67c47ff002b68cf049793faf08 | Patch Third Party Advisory |
https://bugs.debian.org/862571 | Third Party Advisory |
Configurations
Information
Published : 2017-05-15 07:29
Updated : 2017-05-22 20:01
NVD link : CVE-2017-8934
Mitre link : CVE-2017-8934
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
pcmanfm_project
- pcmanfm