{"id":"CVE-2011-3616","details":"The getSkillname function in the eve module in Conky 1.8.1 and earlier allows local users to overwrite arbitrary files via a symlink attack on /tmp/.cesf.","modified":"2026-04-10T03:41:58.804170Z","published":"2011-11-04T21:55:07Z","related":["openSUSE-SU-2024:10093-1"],"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/43225"},{"type":"ADVISORY","url":"http://secunia.com/advisories/46353"},{"type":"EVIDENCE","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612033"},{"type":"WEB","url":"http://www.gentoo.org/security/en/glsa/glsa-201110-09.xml"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/10/09/4"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2011/10/10/8"},{"type":"WEB","url":"https://bugs.launchpad.net/ubuntu/+source/conky/+bug/607309"}],"schema_version":"1.7.5"}