Upstream information
CVE-2011-1588 at MITRE
Description
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| CVSS detail | National Vulnerability Database |
| Base Score | 6.8 |
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| Access Vector | Network |
| Access Complexity | Medium |
| Authentication | None |
| Confidentiality Impact | Partial |
| Integrity Impact | Partial |
| Availability Impact | Partial |
CVSS v3 Scores
| CVSS detail | National Vulnerability Database |
| Base Score | 7.8 |
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| Attack Vector | Local |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | Required |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
SUSE Bugzilla entry:
687874 [RESOLVED / FIXED]
SUSE Security Advisories:
List of released packages
| Product(s) | Fixed package version(s) | References |
| SUSE Package Hub 12 SP2 | exo-branding-upstream >= 0.12.0-2.1
exo-data >= 0.12.0-2.1
exo-devel >= 0.12.0-2.1
exo-helpers >= 0.12.0-2.1
exo-lang >= 0.12.0-2.1
exo-tools >= 0.12.0-2.1
libexo-1-0 >= 0.12.0-2.1
libexo-2-0 >= 0.12.0-2.1
libgarcon-1-0 >= 0.6.1-2.1
libgarcon-branding-upstream >= 0.6.1-2.1
libgarcon-data >= 0.6.1-2.1
libgarcon-devel >= 0.6.1-2.1
libgarcon-doc >= 0.6.1-2.1
libgarcon-lang >= 0.6.1-2.1
libthunarx-2-0 >= 1.6.14-2.1
libxfce4panel-1_0-4 >= 4.12.2-2.1
libxfce4panel-2_0-4 >= 4.12.2-2.1
libxfce4ui-1-0 >= 4.12.1-2.1
libxfce4ui-2-0 >= 4.12.1-2.1
libxfce4ui-branding-upstream >= 4.12.1-2.1
libxfce4ui-devel >= 4.12.1-2.1
libxfce4ui-doc >= 4.12.1-2.1
libxfce4ui-lang >= 4.12.1-2.1
libxfce4ui-tools >= 4.12.1-2.1
libxfce4util-devel >= 4.12.1-2.1
libxfce4util-lang >= 4.12.1-2.1
libxfce4util-tools >= 4.12.1-2.1
libxfce4util7 >= 4.12.1-2.1
libxfconf-0-2 >= 4.12.1-2.1
libxfconf-devel >= 4.12.1-2.1
perl-ExtUtils-Depends >= 0.405-2.1
perl-ExtUtils-PkgConfig >= 1.160000-2.1
perl-Glib >= 1.326-2.1
perl-xfconf >= 4.12.1-2.1
thunar >= 1.6.14-2.1
thunar-devel >= 1.6.14-2.1
thunar-lang >= 1.6.14-2.1
xfce4-dev-tools >= 4.12.0-2.1
xfce4-panel >= 4.12.2-2.1
xfce4-panel-branding-upstream >= 4.12.2-2.1
xfce4-panel-devel >= 4.12.2-2.1
xfce4-panel-lang >= 4.12.2-2.1
xfconf >= 4.12.1-2.1
xfconf-lang >= 4.12.1-2.1
| Patchnames: openSUSE-2019-2305 |
| openSUSE Leap 15.0 | libthunarx-2-0 >= 1.6.14-lp150.1.4
thunar >= 1.6.14-lp150.1.4
thunar-lang >= 1.6.14-lp150.1.4
| Patchnames: openSUSE Leap 15.0 GA libthunarx-2-0-1.6.14-lp150.1.4 |
| openSUSE Tumbleweed | libthunarx-2-0 >= 1.6.10-2.5
thunar >= 1.6.10-2.5
thunar-devel >= 1.6.10-2.5
thunar-lang >= 1.6.10-2.5
| Patchnames: openSUSE-Tumbleweed-2024-10354 |
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 07:58:40 2013
CVE page last modified: Sat Nov 1 19:36:43 2025