GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Oct 16, 2011 7:26 pm Post subject: [ GLSA 201110-09 ] Conky: Privilege escalation |
|
|
Gentoo Linux Security Advisory
Title: Conky: Privilege escalation (GLSA 201110-09)
Severity: normal
Exploitable: local
Date: October 13, 2011
Bug(s): #354061
ID: 201110-09
Synopsis
A privilege escalation vulnerability was found in Conky.
Background
Conky is an advanced, highly configurable system monitor for X.
Affected Packages
Package: app-admin/conky
Vulnerable: < 1.8.1-r2
Unaffected: >= 1.8.1-r2
Architectures: All supported architectures
Description
A privilege escalation vulnerability due to an insecure temporary file
was found in Conky.
Impact
A local attacker could possibly overwrite arbitrary files with the
privileges of the user running Conky.
Workaround
There is no known workaround at this time.
Resolution
All Conky users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-admin/conky-1.8.1-r2"
|
References
CVE-2011-3616 |
|