5
CVSSv2

CVE-2007-6061

Published: 20/11/2007 Updated: 07/02/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 450
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audacityteam audacity 1.3.2

Vendor Advisories

Debian Bug report logs - #453283 CVE-2007-6061: possible symlink attack Package: audacity; Maintainer for audacity is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Source for audacity is src:audacity (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Wed, 28 N ...