~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
Candidate: CVE-2011-1031
PublicDate: 2011-02-14
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1031
Description:
 The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might
 allow local users to create arbitrary files via a symlink attack on a
 /tmp/feh_ temporary file, a different vulnerability than CVE-2011-0702.
Ubuntu-Description:
Notes:
 mdeslaur> maverick+ symlink restrictions may block this
Bugs:
 https://github.com/derf/feh/issues/#issue/32
 https://bugzilla.redhat.com/show_bug.cgi?id=676389
Priority: medium
Discovered-by:
Assigned-to:

Patches_feh:
 upstream: https://derf.homelinux.org/git/feh/commit/?id=23421a86cc826dd30f3dc4f62057fafb04b3ac40
upstream_feh: needs-triage
dapper_feh: ignored (reached end-of-life)
hardy_feh: ignored (reached end-of-life)
karmic_feh: ignored (reached end-of-life)
lucid_feh: ignored (reached end-of-life)
maverick_feh: ignored (reached end-of-life)
natty_feh: ignored (reached end-of-life)
oneiric_feh: ignored (reached end-of-life)
precise_feh: ignored (reached end-of-life)
precise/esm_feh: DNE (precise was needed)
quantal_feh: ignored (reached end-of-life)
raring_feh: ignored (reached end-of-life)
saucy_feh: ignored (reached end-of-life)
trusty_feh: needed
utopic_feh: ignored (reached end-of-life)
vivid_feh: ignored (reached end-of-life)
vivid/stable-phone-overlay_feh: DNE
vivid/ubuntu-core_feh: DNE
wily_feh: ignored (reached end-of-life)
xenial_feh: needed
yakkety_feh: ignored (reached end-of-life)
zesty_feh: needed
devel_feh: needed