← Back

CVE-2020-11867

nvd nist
Published: Nov 30, 2020Modified: Nov 21, 2024

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.

Affected (3)

1 product
Audacity
1 product
Fedora
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.3.3
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 33
Version 34

Timeline

No history available yet.