SB2019111448 - Format string error in xfce-mirror thunar
Published: November 14, 2019 Updated: August 8, 2020
Security Bulletin ID
SB2019111448
Severity
High
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Format string error (CVE-ID: CVE-2011-1588)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Remediation
Install update from vendor's website.
References
- http://lists.opensuse.org/opensuse-security-announce/2011-05/msg00008.html
- https://access.redhat.com/security/cve/cve-2011-1588
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-1588
- https://github.com/xfce-mirror/thunar/blob/master/NEWS#L774
- https://github.com/xfce-mirror/thunar/commit/03dd312e157d4fa8a11d5fa402706ae5b05806fa
- https://security-tracker.debian.org/tracker/CVE-2011-1588