SB2017052218 - Input validation error in libfm (Alpine package)
Published: May 22, 2017
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2017-8934)
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3b71bd4740135cb64c8af1a0abeb1dfbb7aaff7b
- https://git.alpinelinux.org/aports/commit/?id=d276fa6d89a6d82dc00628912b59c814d1715cbc
- https://git.alpinelinux.org/aports/commit/?id=c8d8c044fd84b87d72a5a89cc331d2d1d14c3442
- https://git.alpinelinux.org/aports/commit/?id=f4d50b1370c7d70aa90eb645fe3dad9eb6a8c7dd
- https://git.alpinelinux.org/aports/commit/?id=a28f3503a4b1c9910c9dd1a9984053ba50570029