← Back

CVE-2011-1031

nvd nist
Published: Feb 14, 2011Modified: Apr 29, 2026

JSON object

Loading...
3.3
Vector
AV:L/AC:M/Au:N/C:N/I:P/A:P
Exploitability: 3.4 / Impact: 4.9
Source: NVD

Description

The feh_unique_filename function in utils.c in feh 1.11.2 and earlier might allow local users to create arbitrary files via a symlink attack on a /tmp/feh_ temporary file, a different vulnerability than CVE-2011-0702.

Affected (16)

Products: Feh Project: Feh
1 product
Feh
Configuration A
16 vulnerable
Vulnerable SoftwareAffected Versions
Feh Project
Up to 1.11.2
Version 1.10.1
Version 1.10
Version 1.11.1
Version 1.11
Version 1.3.5
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.4
Version 1.5
Version 1.6.1
Version 1.6
Version 1.7
Version 1.8
Version 1.9

References (10)

Timeline

No history available yet.