Description
The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.
References (7)
Core 7
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43225
Issue Tracking x_refsource_confirm
https://bugs.launchpad.net/ubuntu/+source/conky/+bug/607309
Exploit x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612033
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/09/4
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/10/10/8
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/46353
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-201110-09.xml
Scores
EPSS
0.0042
EPSS Percentile
33.8%
Details
CWE
CWE-59
Status
published
Products (28)
conky/conky
1.1
conky/conky
1.2
conky/conky
1.3.0
conky/conky
1.3.1
conky/conky
1.3.2
conky/conky
1.3.3
conky/conky
1.3.4
conky/conky
1.3.5
conky/conky
1.4.0
conky/conky
1.4.1
... and 18 more
Published
Nov 04, 2011
Tracked Since
Feb 18, 2026