SB2011101302 - Gentoo update for Conky
Published: October 13, 2011 Updated: September 25, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2011-3616)
The vulnerability allows a local non-authenticated attacker to #BASIC_IMPACT#.
The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.
Remediation
Install update from vendor's website.