~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2011-0702

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2011-0702
2
 
PublicDate: 2011-02-14
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0702
5
 
Description:
6
 
 The feh_unique_filename function in utils.c in feh before 1.11.2 might
7
 
 allow local users to overwrite arbitrary files via a symlink attack on a
8
 
 /tmp/feh_ temporary file.
9
 
Ubuntu-Description:
10
 
Notes:
11
 
 mdeslaur> maverick+ may be unaffected because of symlink restrictions
12
 
Bugs:
13
 
 https://bugs.launchpad.net/ubuntu/+source/feh/+bug/607328
14
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612035
15
 
 https://github.com/derf/feh/issues/#issue/32
16
 
 https://bugzilla.redhat.com/show_bug.cgi?id=676389
17
 
Priority: medium
18
 
Discovered-by:
19
 
Assigned-to:
20
 
 
21
 
Patches_feh:
22
 
 upstream: https://derf.homelinux.org/git/feh/commit/?id=23421a86cc826dd30f3dc4f62057fafb04b3ac40
23
 
upstream_feh: released (1.11.2)
24
 
dapper_feh: ignored (reached end-of-life)
25
 
hardy_feh: ignored (reached end-of-life)
26
 
karmic_feh: ignored (reached end-of-life)
27
 
lucid_feh: ignored (reached end-of-life)
28
 
maverick_feh: ignored (reached end-of-life)
29
 
natty_feh: ignored (reached end-of-life)
30
 
oneiric_feh: not-affected (1.13-1)
31
 
precise_feh: not-affected (1.13-1)
32
 
quantal_feh: not-affected (1.13-1)
33
 
raring_feh: not-affected (1.13-1)
34
 
saucy_feh: not-affected (1.13-1)
35
 
devel_feh: not-affected (1.13-1)