Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia: 2021-0001 Moderate: Audacity File Access Concern

mageia
Calendar Grey January 2, 2021
Dist Mageia Esm H88
Mageia has unveiled an Audacity update addressing a critical security flaw involving temporary files, potentially allowing unauthorized user access. More details are available here
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default

Summary

Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867).

References

- https://bugs.mageia.org/show_bug.cgi?id=27850

-

- https://www.cve.org/CVERecord?id=CVE-2020-11867

Resolution

SRPMS

- 7/core/audacity-2.3.1-1.2.mga7

Publication date: 02 Jan 2021
URL: https://advisories.mageia.org/MGASA-2021-0001.html
Type: security
CVE: CVE-2020-11867

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here