Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: 200709-08 Critical: Id3lib Symlink Attack Advisory

gentoo
Calendar Grey September 15, 2007
Dist Gentoo Esm H88
Gentoo advisory GLSA 202310-05 highlights a vulnerability in libarchive affecting file extraction via a symlink exploitation.
A vulnerability has been discovered in id3lib allowing local users to overwrite arbitrary files via a symlink attack.

Summary

Gentoo Linux Security Advisory GLSA 200709-08 https://security.gentoo.org/ Severity: Normal Title: id3lib: Insecure temporary file creation Date: September 15, 2007 Bugs: #189610 ID: 200709-08

Synopsis ======= A vulnerability has been discovered in id3lib allowing local users to overwrite arbitrary files via a symlink attack.
Background ========= id3lib is an open-source, cross-platform software development library for reading, writing, and manipulating ID3v1 and ID3v2 tags.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/id3lib < 3.8.3-r6 >= 3.8.3-r6
========== Nikolaus Schulz discovered that the function RenderV2ToFile() in file src/tag_file.cpp c...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here