CVE-2020-11867
Summary
| CVE | CVE-2020-11867 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-30 22:15:00 UTC |
| Updated | 2023-11-07 03:15:00 UTC |
| Description | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 33 Update: audacity-2.4.2-4.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| The Many Perils of /tmp – Mike Salvatore's Blog |
MISC |
salvatoresecurity.com |
Third Party Advisory |
| Releases · audacity/audacity · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| [SECURITY] Fedora 34 Update: audacity-3.0.2-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: audacity-3.0.2-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: audacity-2.4.2-4.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281658 Fedora Security Update for audacity (FEDORA-2021-1a043ee3d2)
- 750486 OpenSUSE Security Update for audacity (openSUSE-SU-2020:2261-1)