CVE Database
/

CVE-2007-4460

Back to search

CVE-2007-4460

Published: Aug 21, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.

VendorProductVersions

n/a

n/a

affected
n/a

References

26646
third-party-advisory
x_refsource_SECUNIA
SUSE-SR:2007:019
vendor-advisory
x_refsource_SUSE
26818
third-party-advisory
x_refsource_SECUNIA
26536
third-party-advisory
x_refsource_SECUNIA
MDKSA-2007:180
vendor-advisory
x_refsource_MANDRIVA
26987
third-party-advisory
x_refsource_SECUNIA
25372
vdb-entry
x_refsource_BID
GLSA-200709-08
vendor-advisory
x_refsource_GENTOO
1018667
vdb-entry
x_refsource_SECTRACK
26793
third-party-advisory
x_refsource_SECUNIA
DSA-1365
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now