VYPR
Critical severity9.8NVD Advisory· Published Apr 14, 2017· Updated May 13, 2026

CVE-2017-7875

CVE-2017-7875

Description

In wallpaper.c in feh before v2.18.3, if a malicious client pretends to be the E17 window manager, it is possible to trigger an out-of-boundary heap write while receiving an IPC message. An integer overflow leads to a buffer overflow and/or a double free.

Affected products

1
  • cpe:2.3:a:feh_project:feh:*:*:*:*:*:*:*:*
    Range: <=2.18.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.