Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Fedora 26: PCManFM Security Advisory CVE-2016-10369 DOS Issue

fedora
Calendar Grey June 9, 2017
Dist Fedora Esm H88
An issue with LXDE components concerning the file manager pcmanfm has been resolved through updated RPM packages in a Fedora release. A relogin is necessary.
A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS

Summary

PCMan File Manager is an extremly fast and lightweight file manager

which features tabbed browsing and user-friendly interface.

A potential security flaw is found on LXDE products, which create socket under

/tmp with some predictable names, which may leads to DOS. The security flow on

lxterminal is now assigned as CVE-2016-10369. Some other components also had

similar issues. These new rpms should fix these issues. At least relogin is

required to make this fix effect.

[ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1449114

[ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1451070

[ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1451065

su -c 'dnf upgrade pcmanfm' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 1.2.5
Release: 2.fc26
URL: Summary : Extremly fast and lightweight file manager

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here