2.1
CVSSv2

CVE-2020-11867

Published: 30/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Audacity up to and including 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

audacityteam audacity

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #976874 audacity: CVE-2020-11867 Package: src:audacity; Maintainer for src:audacity is Debian Multimedia Maintainers <debian-multimedia@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 8 Dec 2020 20:33:02 UTC Severity: important Tags: pending, security, ups ...
Audacity saves temporary files to /var/tmp/audacity-$USER by default After Audacity creates the temporary directory, it sets its permissions to 755 Any user on the system can read and play the temporary audio au files located there ...