3.3
CVSSv2

CVE-2008-3699

Published: 14/08/2008 Updated: 08/08/2017
CVSS v2 Base Score: 3.3 | Impact Score: 4.9 | Exploitability Score: 3.4
VMScore: 294
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok prior to 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

amarok amarok 1.4.9.1

Vendor Advisories

Dwayne Litzenberger discovered that Amarok created temporary files in an insecure way Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program (CVE-2008-3699) ...