CVE-2020-11867 - log back

CVE-2020-11867 edited at 04 Apr 2022 22:12:28
References
https://salvatoresecurity.com/the-many-perils-of-tmp/
+ https://github.com/audacity/audacity/commit/8bb55b8bbf0f0030224d0bfa1b290c4bc1d91b6a
https://github.com/audacity/audacity/issues/699
https://github.com/audacity/audacity/pull/700
CVE-2020-11867 edited at 12 Dec 2020 17:40:50
References
https://salvatoresecurity.com/the-many-perils-of-tmp/
+ https://github.com/audacity/audacity/issues/699
+ https://github.com/audacity/audacity/pull/700
CVE-2020-11867 edited at 01 Dec 2020 16:15:17
Severity
- Unknown
+ Low
Remote
- Unknown
+ Local
Type
- Unknown
+ Information disclosure
Description
+ Audacity saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.
References
+ https://salvatoresecurity.com/the-many-perils-of-tmp/
Notes
CVE-2020-11867 created at 01 Dec 2020 16:14:38