Audacity Insecure Temporary File Creation Vulnerability
BID:26608
Info
Audacity Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 26608 |
| Class: | Race Condition Error |
| CVE: |
CVE-2007-6061 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 27 2007 12:00AM |
| Updated: | May 12 2008 06:25PM |
| Credit: | Viktor Griph <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 Gentoo Linux Audacity Audacity 1.3.2 |
| Not Vulnerable: | |
Discussion
Audacity Insecure Temporary File Creation Vulnerability
Audacity is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects Audacity 1.3.2; other versions may also be vulnerable.
Audacity is prone to a security vulnerability because it creates temporary files in an insecure manner.
An attacker with local access could potentially exploit this issue to perform symlink attacks, overwriting arbitrary files in the context of the affected application.
Successfully mounting a symlink attack may allow the attacker to delete or corrupt sensitive files, which may result in a denial of service. Other attacks may also be possible.
This issue affects Audacity 1.3.2; other versions may also be vulnerable.
Exploit / POC
Audacity Insecure Temporary File Creation Vulnerability
An attacker uses readily available commands to exploit the issue.
An attacker uses readily available commands to exploit the issue.
Solution / Fix
Audacity Insecure Temporary File Creation Vulnerability
Solution:
Vendor fixes are available. Please see the references for more information.
Solution:
Vendor fixes are available. Please see the references for more information.
References
Audacity Insecure Temporary File Creation Vulnerability
References:
References:
- [Audacity-users] deadlock with bad ownership of temporary directory (fwd) (Viktor Griph)
- Audacity Home Page (Audacity)
- Bugzilla Bug 199751 (Gentoo)