CVE-2007-4460
Publication date 21 August 2007
Last updated 24 July 2024
Ubuntu priority
The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.
Status
Package | Ubuntu Release | Status |
---|---|---|
id3lib3.8.3 | 9.04 jaunty |
Fixed 3.8.3-7ubuntu1
|
8.10 intrepid |
Fixed 3.8.3-7ubuntu1
|
|
8.04 LTS hardy |
Fixed 3.8.3-7ubuntu1
|
|
7.10 gutsy |
Fixed 3.8.3-7ubuntu1
|
|
7.04 feisty | Ignored end of life, was needed | |
6.10 edgy | Ignored end of life, was needed | |
6.06 LTS dapper | Ignored end of life |