Vulnerability Name: | CVE-2020-11867 (CCN-192505) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2020-06-26 | ||||||||||||||||||||||||||||||||||||
Published: | 2020-06-26 | ||||||||||||||||||||||||||||||||||||
Updated: | 2022-01-01 | ||||||||||||||||||||||||||||||||||||
Summary: | Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N) 2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
4.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-276 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-11867 Source: XF Type: UNKNOWN audacity-cve202011867-info-disc(192505) Source: CCN Type: Audacity GIT Repository Audacity 2.4.2 Source: MISC Type: Release Notes, Third Party Advisory https://github.com/audacity/audacity/releases Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-1a043ee3d2 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-8aaccdbb5f Source: MISC Type: Third Party Advisory https://salvatoresecurity.com/the-many-perils-of-tmp/ Source: CCN Type: WhiteSource Vulnerability Database CVE-2020-11867 | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |