Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Tobias Stoeckmann discovered that it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message. . Package : feh Version : 2.12-1+deb8u1 CVE ID : CVE-2017-7875 Tobias Stoeckmann discovered that it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message. For Debian 8 "Jessie", this problem has been fixed in version 2.12-1+deb8u1. We recommend that you upgrade your feh packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Revise feh to resolve a significant security flaw identified by Tobias Stoeckmann, which pertains to out-of-bounds heap write vulnerabilities.. Debian Feh Security Update, Out-Of-Bounds Write, Security Patch, Debian 8 Jessie. . LinuxSecurity.com Team
- update to 2.28 fixes rhbz #1438979 #1444077 and #1602421. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-3ac43a1e15 2018-11-14 03:23:21.954807 --------------------------------------------------------------------------------Name : feh Product : Fedora 28 Version : 2.28 Release : 1.fc28 URL : https://feh.finalrewind.org/ Summary : Fast command line image viewer using Imlib2 Description : feh is a versatile and fast image viewer using imlib2, the premier image file handling library. feh has many features, from simple single file viewing, to multiple file modes using a slide-show or multiple windows. feh supports the creation of montages as index prints with many user-configurable options. --------------------------------------------------------------------------------Update Information: - update to 2.28 fixes rhbz #1438979 #1444077 and #1602421 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 27 2018 Filipe Rosset - 2.28-1 - update to 2.28 fixes rhbz #1438979 #1444077 and #1602421 * Fri Jul 13 2018 Fedora Release Engineering - 2.19.3-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1602421 - feh no longer depends on giblib https://bugzilla.redhat.com/show_bug.cgi?id=1602421 [ 2 ] Bug #1444077 - CVE-2017-7875 feh: Integer overflow in wallpaper.c while receiving an IPC message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1444077 [ 3 ] Bug #1438979 - feh-2.27.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1438979 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-3ac43a1e15' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- update to 2.28 fixes rhbz #1438979 #1444077 and #1602421. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a84b6d0071 2018-11-14 03:11:43.672695 --------------------------------------------------------------------------------Name : feh Product : Fedora 29 Version : 2.28 Release : 1.fc29 URL : https://feh.finalrewind.org/ Summary : Fast command line image viewer using Imlib2 Description : feh is a versatile and fast image viewer using imlib2, the premier image file handling library. feh has many features, from simple single file viewing, to multiple file modes using a slide-show or multiple windows. feh supports the creation of montages as index prints with many user-configurable options. --------------------------------------------------------------------------------Update Information: - update to 2.28 fixes rhbz #1438979 #1444077 and #1602421 --------------------------------------------------------------------------------ChangeLog: * Sat Oct 27 2018 Filipe Rosset - 2.28-1 - update to 2.28 fixes rhbz #1438979 #1444077 and #1602421 --------------------------------------------------------------------------------References: [ 1 ] Bug #1602421 - feh no longer depends on giblib https://bugzilla.redhat.com/show_bug.cgi?id=1602421 [ 2 ] Bug #1444077 - CVE-2017-7875 feh: Integer overflow in wallpaper.c while receiving an IPC message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1444077 [ 3 ] Bug #1438979 - feh-2.27.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1438979 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a84b6d0071' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A vulnerability in feh might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201707-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: feh: Arbitrary remote code execution Date: July 08, 2017 Bugs: #616470 ID: 201707-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in feh might allow remote attackers to execute arbitrary code. Background ========= feh is an X11 image viewer aimed mostly at console users. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/feh < 2.18.3 > = 2.18.3 Description ========== Tobias Stoeckmann discovered it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message. Impact ===== A remote attacker, pretending to be the E17 window manager, could possibly trigger an out-of-boundary heap write in feh while receiving an IPC message. This could result in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All feh users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/feh-2.18.3" References ========= [ 1 ] CVE-2017-7875 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7875 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201707-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Tobias Stoeckmann discovered it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message. . Hash: SHA512 Package : feh Version : 2.3-2+deb7u1 CVE ID : CVE-2017-7875 Debian Bug : 860367 Tobias Stoeckmann discovered it was possible to trigger an out-of-boundary heap write with the image viewer feh while receiving an IPC message. For Debian 7 "Wheezy", these problems have been fixed in version 2.3-2+deb7u1. We recommend that you upgrade your feh packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Elena Martinez identified a buffer overflow vulnerability in coolApp. Update to version 1.5.4-1+deb9u2 for Debian 9.. Debian LTS, Feh Fix, Image Viewer Update, IPC Message Issue. . LinuxSecurity.com Team
Multiple vulnerabilities were found in feh, the worst of which leading to remote passive code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201110-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: feh: Multiple vulnerabilities Date: October 13, 2011 Bugs: #325531, #354063 ID: 201110-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities were found in feh, the worst of which leading to remote passive code execution. Background ========= feh is a fast, lightweight imageviewer using imlib2. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/feh < 1.12 > = 1.12 Description ========== Multiple vulnerabilities have been discovered in feh. Please review the CVE identifiers referenced below for details. Impact ===== A malicious entity might entice a user to visit a URL using the --wget-timestamp option, thus executing arbitrary commands via shell metacharacters; a malicious local user could perform a symlink attack and overwrite arbitrary files. Workaround ========= There is no known workaround at this time. Resolution ========= All feh users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/feh-1.12" References ========= [ 1 ] CVE-2010-2246 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2246 [ 2 ] CVE-2011-0702 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0702 [ 3 ] CVE-2011-1031 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1031 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201110-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.