Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-1934

Опубликовано: 08 мая 2014
Источник: debian

Описание

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
eyed3fixed0.6.18-3package
eyed3no-dsasqueezepackage

Примечания

  • Upstream patch: https://bitbucket.org/nicfit/eyed3/commits/372bbacb7a70

  • https://bitbucket.org/nicfit/eyed3/issue/65/tagpy-in-eyed3-allows-local-users-to

  • Neutralised by protected_symlinks kernel temp hardening

Связанные уязвимости

ubuntu
больше 11 лет назад

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

nvd
больше 11 лет назад

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

CVSS3: 4.5
github
больше 3 лет назад

eyeD3 is vulnerable to arbitrary file modification via symlink attack