MGASA-2017-0137
Dashboard / Vulnerabilities / MGASA-2017-0137
Summary: Updated feh package fixes security vulnerability
Details: Updated feh package to fix a double-free/OOB-write in E17 IPC. This was a potential security issue as a malicious X11 app running alongside feh and pretending to be an E17 window manager could have had access to out-of-bound memory. Security vulnerability: CVE-2017-7875
References: https://advisories.mageia.org/MGASA-2017-0137.html, https://bugs.mageia.org/show_bug.cgi?id=20775, https://feh.finalrewind.org/, https://lists.opensuse.org/opensuse-updates/2017-05/msg00000.html
Affected packages
Package
Name: feh
Purl: pkg:rpm/mageia/feh?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.18.3-1.mga5
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
