Vulnerability Name: CVE-2014-1934 (CCN-94040) Assigned: 2014-02-10 Published: 2014-02-10 Updated: 2018-10-30 Summary: tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file. CVSS v3 Severity: 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 3.3 Low (CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P )3.2 Low (Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
3.6 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P )3.4 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P/E:H/RL:U/RC:UR )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-59 Vulnerability Consequences: File Manipulation References: Source: MITRE Type: CNACVE-2014-1934 Source: CCN Type: eyeD3 Web siteeyeD3 Source: SUSE Type: UNKNOWNopenSUSE-SU-2014:0619 Source: SUSE Type: UNKNOWNopenSUSE-SU-2014:0620 Source: CCN Type: oss-security Mailing List, Mon, 10 Feb 2014 23:21:00 +0100CVE requests: Pacemaker, Python Imaging Library, eyeD3, 9base, rc, Gamera, RPLY - insecure use of /tmp Source: CCN Type: BID-65480eyeD3 Insecure Temporary File Creation Vulnerability Source: CONFIRM Type: UNKNOWNhttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737062 Source: CONFIRM Type: UNKNOWNhttps://bugzilla.redhat.com/show_bug.cgi?id=1063671 Source: XF Type: UNKNOWNeyed3-cve20141934-symlink(94040) Source: CCN Type: WhiteSource Vulnerability DatabaseCVE-2014-1934 Vulnerable Configuration: Configuration 1 :cpe:/a:travis_shirk:eyed3:0.1.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.2.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.3.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.3.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.4.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.5.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.5.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.0:-:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.0:rc1:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.2:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.3:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.4:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.5:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.6:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.8:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.9:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.10:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.11:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.12:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.13:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.14:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.15:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.16:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.17:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:*:*:*:*:*:*:*:* (Version <= 0.6.18) OR cpe:/a:travis_shirk:eyed3:0.7.3:*:*:*:*:*:*:* OR cpe:/o:opensuse:opensuse:12.3:*:*:*:*:*:*:* OR cpe:/o:opensuse:opensuse:13.1:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/o:opensuse:opensuse:12.3:*:*:*:*:*:*:* OR cpe:/o:opensuse:opensuse:13.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.17:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.16:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.15:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.14:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.13:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.12:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.11:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.10:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.9:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.8:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.6:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.5:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.4:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.3:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.2:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.0:-:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.6.0:rc1:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.5.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.5.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.4.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.3.1:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.3.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.2.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.1.0:*:*:*:*:*:*:* OR cpe:/a:travis_shirk:eyed3:0.7.3:*:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions BACK
travis_shirk eyed3 0.1.0
travis_shirk eyed3 0.2.0
travis_shirk eyed3 0.3.0
travis_shirk eyed3 0.3.1
travis_shirk eyed3 0.4.0
travis_shirk eyed3 0.5.0
travis_shirk eyed3 0.5.1
travis_shirk eyed3 0.6.0 -
travis_shirk eyed3 0.6.0 rc1
travis_shirk eyed3 0.6.1
travis_shirk eyed3 0.6.2
travis_shirk eyed3 0.6.3
travis_shirk eyed3 0.6.4
travis_shirk eyed3 0.6.5
travis_shirk eyed3 0.6.6
travis_shirk eyed3 0.6.8
travis_shirk eyed3 0.6.9
travis_shirk eyed3 0.6.10
travis_shirk eyed3 0.6.11
travis_shirk eyed3 0.6.12
travis_shirk eyed3 0.6.13
travis_shirk eyed3 0.6.14
travis_shirk eyed3 0.6.15
travis_shirk eyed3 0.6.16
travis_shirk eyed3 0.6.17
travis_shirk eyed3 *
travis_shirk eyed3 0.7.3
opensuse opensuse 12.3
opensuse opensuse 13.1
opensuse opensuse 12.3
opensuse opensuse 13.1
travis_shirk eyed3 0.6.17
travis_shirk eyed3 0.6.16
travis_shirk eyed3 0.6.15
travis_shirk eyed3 0.6.14
travis_shirk eyed3 0.6.13
travis_shirk eyed3 0.6.12
travis_shirk eyed3 0.6.11
travis_shirk eyed3 0.6.10
travis_shirk eyed3 0.6.9
travis_shirk eyed3 0.6.8
travis_shirk eyed3 0.6.6
travis_shirk eyed3 0.6.5
travis_shirk eyed3 0.6.4
travis_shirk eyed3 0.6.3
travis_shirk eyed3 0.6.2
travis_shirk eyed3 0.6.1
travis_shirk eyed3 0.6.0 -
travis_shirk eyed3 0.6.0 rc1
travis_shirk eyed3 0.5.1
travis_shirk eyed3 0.5.0
travis_shirk eyed3 0.4.0
travis_shirk eyed3 0.3.1
travis_shirk eyed3 0.3.0
travis_shirk eyed3 0.2.0
travis_shirk eyed3 0.1.0
travis_shirk eyed3 0.7.3