CVE-2011-3616

Conky <1.8.1 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.

References (7)

Core 7
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43225
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/09/4
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/10/8
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46353
Third Party Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-201110-09.xml

Scores

EPSS 0.0042
EPSS Percentile 33.8%

Details

CWE
CWE-59
Status published
Products (28)
conky/conky 1.1
conky/conky 1.2
conky/conky 1.3.0
conky/conky 1.3.1
conky/conky 1.3.2
conky/conky 1.3.3
conky/conky 1.3.4
conky/conky 1.3.5
conky/conky 1.4.0
conky/conky 1.4.1
... and 18 more
Published Nov 04, 2011
Tracked Since Feb 18, 2026