CVE-2020-11867

Name
CVE-2020-11867
Description
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Release Notes https://github.com/audacity/audacity/releases
Third Party Advisory https://salvatoresecurity.com/the-many-perils-of-tmp/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WKK3S2QBXBHOFOQMXMGY5QAKVUWUX2YY/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MG5PSF4CJ7UPMJHWX553EG3P2XN3PAYI/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:audacityteam:audacity:*:*:*:*:*:*:*:* audacity >= None <= 2.3.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status