4.6
CVSSv2

CVE-2008-3791

Published: 03/09/2008 Updated: 17/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

lxde lightweight x11 desktop environment 0.1.9

Vendor Advisories

Debian Bug report logs - #497005 gpicview not confirms to save images Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnocom> Date: Fri, 29 Aug 2008 06: ...
Debian Bug report logs - #498022 gpicview: CVE-2008-3904 arbitrary code execution via crafted file name Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnoco ...
Debian Bug report logs - #495968 gpicview: CVE-2008-3791 insecure temporary file usage Package: gpicview; Maintainer for gpicview is Debian LXDE Maintainers <pkg-lxde-maintainers@listsaliothdebianorg>; Source for gpicview is src:gpicview (PTS, buildd, popcon) Reported by: Wen-Yen Chuang <caleb@calnocom> Date: Thu ...