CVE detail
CVE-2011-3154 — CVE-2011-3154
Published 2014-04-17 · Modified 2026-06-16 · Vendor canonical · Product update-manager · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0033
EPSS probability
exploitation probability, 30d
25.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a symlink attack on the temporary file.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References