3.6
CVSSv2

CVE-2012-3355

Published: 17/07/2012 Updated: 29/08/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and previous versions allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome rhythmbox 0.12.8

gnome rhythmbox 0.12.7

gnome rhythmbox 0.12.6

gnome rhythmbox 0.11.6

gnome rhythmbox 0.11.5

gnome rhythmbox 0.10.0

gnome rhythmbox 0.10.0.90

gnome rhythmbox 0.9.3

gnome rhythmbox 0.9.3.1

gnome rhythmbox 0.8.5

gnome rhythmbox 0.8.4

gnome rhythmbox 0.7.0

gnome rhythmbox 0.6.8

gnome rhythmbox 0.6.0

gnome rhythmbox 0.5.88

gnome rhythmbox 0.13.1

gnome rhythmbox 0.13.0

gnome rhythmbox 0.12.1

gnome rhythmbox 0.12.0

gnome rhythmbox 0.11.0

gnome rhythmbox 0.10.1

gnome rhythmbox 0.9.5

gnome rhythmbox 0.9.4

gnome rhythmbox 0.9.4.1

gnome rhythmbox 0.8.7

gnome rhythmbox 0.8.6

gnome rhythmbox 0.7.2

gnome rhythmbox 0.7.1

gnome rhythmbox 0.6.3

gnome rhythmbox 0.6.2

gnome rhythmbox 0.6.1

gnome rhythmbox 0.5.0

gnome rhythmbox 0.12.5

gnome rhythmbox 0.12.4

gnome rhythmbox 0.11.4

gnome rhythmbox 0.11.3

gnome rhythmbox 0.9.8

gnome rhythmbox 0.9.7

gnome rhythmbox 0.9.2

gnome rhythmbox 0.9.1

gnome rhythmbox 0.8.3

gnome rhythmbox 0.8.2

gnome rhythmbox 0.6.7

gnome rhythmbox 0.6.6

gnome rhythmbox 0.5.4

gnome rhythmbox 0.5.3

gnome rhythmbox

gnome rhythmbox 0.13.2

gnome rhythmbox 0.12.3

gnome rhythmbox 0.12.2

gnome rhythmbox 0.11.2

gnome rhythmbox 0.11.1

gnome rhythmbox 0.9.6

gnome rhythmbox 0.9.6.90

gnome rhythmbox 0.9.0

gnome rhythmbox 0.8.8

gnome rhythmbox 0.8.1

gnome rhythmbox 0.8.0

gnome rhythmbox 0.6.5

gnome rhythmbox 0.6.4

gnome rhythmbox 0.5.2

gnome rhythmbox 0.5.1

Vendor Advisories

Debian Bug report logs - #616673 rhythmbox-plugins: CVE-2012-3355 Plugin "context" contains hardcoded path to /tmp/context/ Package: rhythmbox-plugins; Maintainer for rhythmbox-plugins is Debian GNOME Maintainers <pkg-gnome-maintainers@listsaliothdebianorg>; Source for rhythmbox-plugins is src:rhythmbox (PTS, buildd, popcon) ...
Rhythmbox could be made to run programs as your login when using the Context plugin ...