Upstream information
CVE-2011-1588 at MITRE
Description
Thunar before 1.3.1 could crash when copy and pasting a file name with % format characters due to a format string error.
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
CVSS v2 Scores
| CVSS detail |  National Vulnerability Database | 
| Base Score |  6.8 | 
| Vector |  AV:N/AC:M/Au:N/C:P/I:P/A:P | 
| Access Vector |  Network | 
| Access Complexity |  Medium | 
| Authentication |  None | 
| Confidentiality Impact |  Partial | 
| Integrity Impact |  Partial | 
| Availability Impact |  Partial | 
CVSS v3 Scores
| CVSS detail |  National Vulnerability Database | 
| Base Score |  7.8 | 
| Vector |  CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H | 
| Attack Vector |  Local | 
| Attack Complexity |  Low | 
| Privileges Required |  None | 
| User Interaction |  Required | 
| Scope |  Unchanged | 
| Confidentiality Impact |  High | 
| Integrity Impact |  High | 
| Availability Impact |  High | 
| CVSSv3 Version |  3.1 | 
SUSE Bugzilla entry: 
687874 [RESOLVED / FIXED]
SUSE Security Advisories:
List of released packages
| Product(s) |  Fixed package version(s) |  References | 
| SUSE Package Hub 12 SP2 |  exo-branding-upstream >= 0.12.0-2.1 
 exo-data >= 0.12.0-2.1 
 exo-devel >= 0.12.0-2.1 
 exo-helpers >= 0.12.0-2.1 
 exo-lang >= 0.12.0-2.1 
 exo-tools >= 0.12.0-2.1 
 libexo-1-0 >= 0.12.0-2.1 
 libexo-2-0 >= 0.12.0-2.1 
 libgarcon-1-0 >= 0.6.1-2.1 
 libgarcon-branding-upstream >= 0.6.1-2.1 
 libgarcon-data >= 0.6.1-2.1 
 libgarcon-devel >= 0.6.1-2.1 
 libgarcon-doc >= 0.6.1-2.1 
 libgarcon-lang >= 0.6.1-2.1 
 libthunarx-2-0 >= 1.6.14-2.1 
 libxfce4panel-1_0-4 >= 4.12.2-2.1 
 libxfce4panel-2_0-4 >= 4.12.2-2.1 
 libxfce4ui-1-0 >= 4.12.1-2.1 
 libxfce4ui-2-0 >= 4.12.1-2.1 
 libxfce4ui-branding-upstream >= 4.12.1-2.1 
 libxfce4ui-devel >= 4.12.1-2.1 
 libxfce4ui-doc >= 4.12.1-2.1 
 libxfce4ui-lang >= 4.12.1-2.1 
 libxfce4ui-tools >= 4.12.1-2.1 
 libxfce4util-devel >= 4.12.1-2.1 
 libxfce4util-lang >= 4.12.1-2.1 
 libxfce4util-tools >= 4.12.1-2.1 
 libxfce4util7 >= 4.12.1-2.1 
 libxfconf-0-2 >= 4.12.1-2.1 
 libxfconf-devel >= 4.12.1-2.1 
 perl-ExtUtils-Depends >= 0.405-2.1 
 perl-ExtUtils-PkgConfig >= 1.160000-2.1 
 perl-Glib >= 1.326-2.1 
 perl-xfconf >= 4.12.1-2.1 
 thunar >= 1.6.14-2.1 
 thunar-devel >= 1.6.14-2.1 
 thunar-lang >= 1.6.14-2.1 
 xfce4-dev-tools >= 4.12.0-2.1 
 xfce4-panel >= 4.12.2-2.1 
 xfce4-panel-branding-upstream >= 4.12.2-2.1 
 xfce4-panel-devel >= 4.12.2-2.1 
 xfce4-panel-lang >= 4.12.2-2.1 
 xfconf >= 4.12.1-2.1 
 xfconf-lang >= 4.12.1-2.1 
  |  Patchnames:  openSUSE-2019-2305 | 
| openSUSE Leap 15.0 |  libthunarx-2-0 >= 1.6.14-lp150.1.4 
 thunar >= 1.6.14-lp150.1.4 
 thunar-lang >= 1.6.14-lp150.1.4 
  |  Patchnames:  openSUSE Leap 15.0 GA libthunarx-2-0-1.6.14-lp150.1.4 | 
| openSUSE Tumbleweed |  libthunarx-2-0 >= 1.6.10-2.5 
 thunar >= 1.6.10-2.5 
 thunar-devel >= 1.6.10-2.5 
 thunar-lang >= 1.6.10-2.5 
  |  Patchnames:  openSUSE-Tumbleweed-2024-10354 | 
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 07:58:40 2013
CVE page last modified: Sat Nov  1 19:36:43 2025