CVE-2008-3699

The MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file.
References
Link Resource
http://amarok.kde.org/en/releases/1/4/10
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765
http://secunia.com/advisories/31418 Vendor Advisory
http://secunia.com/advisories/31663
http://secunia.com/advisories/31839
http://secunia.com/advisories/32357
http://security.gentoo.org/glsa/glsa-200809-08.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.455790
http://websvn.kde.org/?view=rev&revision=846626
http://www.mandriva.com/security/advisories?name=MDVSA-2008:172
http://www.securityfocus.com/bid/30662
http://www.ubuntu.com/usn/usn-657-1
http://www.vupen.com/english/advisories/2008/2338
https://exchange.xforce.ibmcloud.com/vulnerabilities/44399
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00057.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00097.html
http://amarok.kde.org/en/releases/1/4/10
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765
http://secunia.com/advisories/31418 Vendor Advisory
http://secunia.com/advisories/31663
http://secunia.com/advisories/31839
http://secunia.com/advisories/32357
http://security.gentoo.org/glsa/glsa-200809-08.xml
http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.455790
http://websvn.kde.org/?view=rev&revision=846626
http://www.mandriva.com/security/advisories?name=MDVSA-2008:172
http://www.securityfocus.com/bid/30662
http://www.ubuntu.com/usn/usn-657-1
http://www.vupen.com/english/advisories/2008/2338
https://exchange.xforce.ibmcloud.com/vulnerabilities/44399
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00057.html
https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00097.html
Configurations

Configuration 1 (hide)

cpe:2.3:a:amarok:amarok:1.4.9.1:*:*:*:*:*:*:*

History

21 Nov 2024, 00:49

Type Values Removed Values Added
References () http://amarok.kde.org/en/releases/1/4/10 - () http://amarok.kde.org/en/releases/1/4/10 -
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765 -
References () http://secunia.com/advisories/31418 - Vendor Advisory () http://secunia.com/advisories/31418 - Vendor Advisory
References () http://secunia.com/advisories/31663 - () http://secunia.com/advisories/31663 -
References () http://secunia.com/advisories/31839 - () http://secunia.com/advisories/31839 -
References () http://secunia.com/advisories/32357 - () http://secunia.com/advisories/32357 -
References () http://security.gentoo.org/glsa/glsa-200809-08.xml - () http://security.gentoo.org/glsa/glsa-200809-08.xml -
References () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.455790 - () http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.455790 -
References () http://websvn.kde.org/?view=rev&revision=846626 - () http://websvn.kde.org/?view=rev&revision=846626 -
References () http://www.mandriva.com/security/advisories?name=MDVSA-2008:172 - () http://www.mandriva.com/security/advisories?name=MDVSA-2008:172 -
References () http://www.securityfocus.com/bid/30662 - () http://www.securityfocus.com/bid/30662 -
References () http://www.ubuntu.com/usn/usn-657-1 - () http://www.ubuntu.com/usn/usn-657-1 -
References () http://www.vupen.com/english/advisories/2008/2338 - () http://www.vupen.com/english/advisories/2008/2338 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/44399 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/44399 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00057.html - () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00057.html -
References () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00097.html - () https://www.redhat.com/archives/fedora-package-announce/2008-September/msg00097.html -

Information

Published : 2008-08-14 23:41

Updated : 2024-11-21 00:49


NVD link : CVE-2008-3699

Mitre link : CVE-2008-3699

CVE.ORG link : CVE-2008-3699


JSON object : View

Products Affected

amarok

  • amarok
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')