{"api_version":"1","generated_at":"2026-07-24T18:54:55+00:00","cve":"CVE-2020-11867","urls":{"html":"https://cve.report/CVE-2020-11867","api":"https://cve.report/api/cve/CVE-2020-11867.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-11867","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-11867"},"summary":{"title":"CVE-2020-11867","description":"Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-11-30 22:15:00","updated_at":"2023-11-07 03:15:00"},"problem_types":["CWE-276"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WKK3S2QBXBHOFOQMXMGY5QAKVUWUX2YY/","name":"FEDORA-2021-8aaccdbb5f","refsource":"","tags":[],"title":"[SECURITY] Fedora 33 Update: audacity-2.4.2-4.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://salvatoresecurity.com/the-many-perils-of-tmp/","name":"https://salvatoresecurity.com/the-many-perils-of-tmp/","refsource":"MISC","tags":["Third Party Advisory"],"title":"The Many Perils of /tmp – Mike Salvatore's Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/audacity/audacity/releases","name":"https://github.com/audacity/audacity/releases","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"Releases · audacity/audacity · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MG5PSF4CJ7UPMJHWX553EG3P2XN3PAYI/","name":"FEDORA-2021-1a043ee3d2","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: audacity-3.0.2-3.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MG5PSF4CJ7UPMJHWX553EG3P2XN3PAYI/","name":"FEDORA-2021-1a043ee3d2","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: audacity-3.0.2-3.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WKK3S2QBXBHOFOQMXMGY5QAKVUWUX2YY/","name":"FEDORA-2021-8aaccdbb5f","refsource":"FEDORA","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 33 Update: audacity-2.4.2-4.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-11867","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11867","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"11867","vulnerable":"1","versionEndIncluding":"2.3.3","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"audacityteam","cpe5":"audacity","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11867","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11867","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"11867","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-11867","qid":"281658","title":"Fedora Security Update for audacity (FEDORA-2021-1a043ee3d2)"},{"cve":"CVE-2020-11867","qid":"750486","title":"OpenSUSE Security Update for audacity (openSUSE-SU-2020:2261-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-11867","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/audacity/audacity/releases","refsource":"MISC","name":"https://github.com/audacity/audacity/releases"},{"refsource":"MISC","name":"https://salvatoresecurity.com/the-many-perils-of-tmp/","url":"https://salvatoresecurity.com/the-many-perils-of-tmp/"},{"refsource":"FEDORA","name":"FEDORA-2021-8aaccdbb5f","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WKK3S2QBXBHOFOQMXMGY5QAKVUWUX2YY/"},{"refsource":"FEDORA","name":"FEDORA-2021-1a043ee3d2","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MG5PSF4CJ7UPMJHWX553EG3P2XN3PAYI/"}]}},"nvd":{"publishedDate":"2020-11-30 22:15:00","lastModifiedDate":"2023-11-07 03:15:00","problem_types":["CWE-276"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"},"exploitabilityScore":1.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:audacityteam:audacity:*:*:*:*:*:*:*:*","versionEndIncluding":"2.3.3","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"11867","Ordinal":"172692","Title":"CVE-2020-11867","CVE":"CVE-2020-11867","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"11867","Ordinal":"1","NoteData":"Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"11867","Ordinal":"2","NoteData":"2020-11-30","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"11867","Ordinal":"3","NoteData":"2021-06-21","Type":"Other","Title":"Modified"}]}}}