mpeg-tools before 1.5b-r2 creates multiple temporary files insecurely, which allows local users to overwrite arbitrary files via (1) ts.stat, (2) ts.mpg, (3) foobar, (4) blockbar, or (5) foobar[NNN].
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mpeg-tools | Mpeg-tools | * | 1.5b_r1 (including) |