Vulnerability Description
feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Feh Project | Feh | <= 1.7 |
Related Weaknesses (CWE)
References
- http://derf.homelinux.org/git/feh/plain/ChangeLog
- http://openwall.com/lists/oss-security/2010/06/25/4Exploit
- http://openwall.com/lists/oss-security/2010/06/28/4Exploit
- http://www.securityfocus.com/bid/41161Exploit
- http://derf.homelinux.org/git/feh/plain/ChangeLog
- http://openwall.com/lists/oss-security/2010/06/25/4Exploit
- http://openwall.com/lists/oss-security/2010/06/28/4Exploit
- http://www.securityfocus.com/bid/41161Exploit
FAQ
What is CVE-2010-2246?
CVE-2010-2246 is a vulnerability with a CVSS score of 5.1 (MEDIUM). feh before 1.8, when the --wget-timestamp option is enabled, might allow remote attackers to execute arbitrary commands via shell metacharacters in a URL.
How severe is CVE-2010-2246?
CVE-2010-2246 has been rated MEDIUM with a CVSS base score of 5.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2246?
Check the references section above for vendor advisories and patch information. Affected products include: Feh Project Feh.