KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
BID:14805
Info
KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 14805 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2005 12:00AM |
| Updated: | Sep 12 2005 12:00AM |
| Credit: | SUSE announced this vulnerability. |
| Vulnerable: |
S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 KAudioCreator KAudioCreator |
| Not Vulnerable: | |
Discussion
KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
KAudioCreator is prone to an arbitrary file overwrite vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to overwrite arbitrary files in the security context of the user running the vulnerable application.
KAudioCreator is prone to an arbitrary file overwrite vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to overwrite arbitrary files in the security context of the user running the vulnerable application.
Exploit / POC
KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
Solution:
SUSE has released a security summary report (SUSE-SR:2005:020) addressing this and other issues. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
SUSE has released a security summary report (SUSE-SR:2005:020) addressing this and other issues. Please see the referenced advisory for further information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
KAudioCreator CDDB Arbitrary File Overwrite Vulnerability
References:
References: