Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Audacity could expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-7211-1 January 16, 2025 audacity vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Audacity could expose sensitive information. Software Description: - audacity: fast, cross-platform audio editor Details: Mike Salvatore discovered that Audacity incorrectly handled default permissions of temporary files created by the application. An attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS audacity 2.3.3-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS audacity 2.2.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS audacity 2.1.2-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7211-1 CVE-2020-11867 . Important security vulnerability found in Audacity on Ubuntu versions 20.04, 18.04, and 16.04. Ensure you upgrade to the latest package releases to resolve this concern.. audacity security, Ubuntu updates, information exposure, Ubuntu Pro, software vulnerability. . Severity: Critical. LinuxSecurity.com Team
- Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Fix CVE-2020-1867 (fixes rhbz #1904016). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1a043ee3d2 2021-06-22 01:01:06.903238 --------------------------------------------------------------------------------Name : audacity Product : Fedora 34 Version : 3.0.2 Release : 3.fc34 URL : https://www.audacityteam.org/ Summary : Multitrack audio editor Description : Audacity is a cross-platform multitrack audio editor. It allows you to record sounds directly or to import files in various formats. It features a few simple effects, all of the editing features you should need, and unlimited undo. The GUI was built with wxWidgets and the audio I/O supports PulseAudio, OSS and ALSA under Linux. --------------------------------------------------------------------------------Update Information: - Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Fix CVE-2020-1867 (fixes rhbz #1904016) --------------------------------------------------------------------------------ChangeLog: * Thu Jun 17 2021 Ian McInerney - 3.0.2-3 - Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Temporarily disable the rpath checks until upstream fixes it - Fix CVE-2020-1867 (fixes rhbz #1904016) --------------------------------------------------------------------------------References: [ 1 ] Bug #1904016 - CVE-2020-11867 audacity: insecure use of temporary directory leads to information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1904016 [ 2 ] Bug #1972963 - audacity: no jack host listed via pipewire https://bugzilla.redhat.com/show_bug.cgi?id=1972963 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1a043ee3d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867). . MGASA-2021-0001 - Updated audacity package fixes security vulnerability Publication date: 02 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0001.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11867 Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867). References: - https://bugs.mageia.org/show_bug.cgi?id=27850 - - https://www.cve.org/CVERecord?id=CVE-2020-11867 SRPMS: - 7/core/audacity-2.3.1-1.2.mga7 . Mageia has unveiled an Audacity update addressing a critical security flaw involving temporary files, potentially allowing unauthorized user access. More details are available here. Mageia Security, Audacity Update, File Permissions. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for audacity ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2261-1 Rating: moderate References: #1179449 Cross-References: CVE-2020-11867 Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 openSUSE Backports SLE-15-SP2 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for audacity fixes the following issues: - CVE-2020-11867: Avoid saving temporary files to /var/tmp/audacity-$USER by default, which permissions are set to 755. (bsc#1179449) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-2261=1 Package List: - openSUSE Leap 15.2 (noarch): audacity-lang-2.2.2-lp152.4.3.1 - openSUSE Leap 15.2 (x86_64): audacity-2.2.2-lp152.4.3.1 audacity-debuginfo-2.2.2-lp152.4.3.1 audacity-debugsource-2.2.2-lp152.4.3.1 - openSUSE Leap 15.1 (noarch): audacity-lang-2.2.2-lp151.3.3.1 - openSUSE Leap 15.1 (x86_64): audacity-2.2.2-lp151.3.3.1 audacity-debuginfo-2.2.2-lp151.3.3.1 audacity-debugsource-2.2.2-lp151.3.3.1 - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390xx86_64): audacity-2.2.2-bp152.4.3.1 audacity-debuginfo-2.2.2-bp152.4.3.1 audacity-debugsource-2.2.2-bp152.4.3.1 - openSUSE Backports SLE-15-SP2 (noarch): audacity-lang-2.2.2-bp152.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): audacity-2.2.2-bp151.4.3.1 - openSUSE Backports SLE-15-SP1 (noarch): audacity-lang-2.2.2-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-11867.html https://bugzilla.suse.com/1179449 _______________________________________________ openSUSE Security Announce mailing list --
A boundary error in Audacity allows for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Audacity: User-assisted execution of arbitrary code Date: March 06, 2009 Bugs: #253493 ID: 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A boundary error in Audacity allows for the execution of arbitrary code. Background ========= Audacity is a free cross-platform audio editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/audacity < 1.3.6 > = 1.3.6 Description ========== Houssamix discovered a boundary error in the String_parse::get_nonspace_quoted() function in lib-src/allegro/strparse.cpp. Impact ===== A remote attacker could entice a user into importing a specially crafted *.gro file, resulting in the execution of arbitrary code or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Audacity users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/audacity-1.3.6" References ========= [ 1 ] CVE-2009-0490 https://www.cve.org/CVERecord?id=CVE-2009-0490 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.