tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Eyed3 | Travis_shirk | * | 0.6.18 (including) |
Eyed3 | Travis_shirk | 0.1.0 (including) | 0.1.0 (including) |
Eyed3 | Travis_shirk | 0.2.0 (including) | 0.2.0 (including) |
Eyed3 | Travis_shirk | 0.3.0 (including) | 0.3.0 (including) |
Eyed3 | Travis_shirk | 0.3.1 (including) | 0.3.1 (including) |
Eyed3 | Travis_shirk | 0.4.0 (including) | 0.4.0 (including) |
Eyed3 | Travis_shirk | 0.5.0 (including) | 0.5.0 (including) |
Eyed3 | Travis_shirk | 0.5.1 (including) | 0.5.1 (including) |
Eyed3 | Travis_shirk | 0.6.0 (including) | 0.6.0 (including) |
Eyed3 | Travis_shirk | 0.6.0-rc1 (including) | 0.6.0-rc1 (including) |
Eyed3 | Travis_shirk | 0.6.1 (including) | 0.6.1 (including) |
Eyed3 | Travis_shirk | 0.6.2 (including) | 0.6.2 (including) |
Eyed3 | Travis_shirk | 0.6.3 (including) | 0.6.3 (including) |
Eyed3 | Travis_shirk | 0.6.4 (including) | 0.6.4 (including) |
Eyed3 | Travis_shirk | 0.6.5 (including) | 0.6.5 (including) |
Eyed3 | Travis_shirk | 0.6.6 (including) | 0.6.6 (including) |
Eyed3 | Travis_shirk | 0.6.8 (including) | 0.6.8 (including) |
Eyed3 | Travis_shirk | 0.6.9 (including) | 0.6.9 (including) |
Eyed3 | Travis_shirk | 0.6.10 (including) | 0.6.10 (including) |
Eyed3 | Travis_shirk | 0.6.11 (including) | 0.6.11 (including) |
Eyed3 | Travis_shirk | 0.6.12 (including) | 0.6.12 (including) |
Eyed3 | Travis_shirk | 0.6.13 (including) | 0.6.13 (including) |
Eyed3 | Travis_shirk | 0.6.14 (including) | 0.6.14 (including) |
Eyed3 | Travis_shirk | 0.6.15 (including) | 0.6.15 (including) |
Eyed3 | Travis_shirk | 0.6.16 (including) | 0.6.16 (including) |
Eyed3 | Travis_shirk | 0.6.17 (including) | 0.6.17 (including) |
Eyed3 | Travis_shirk | 0.7.3 (including) | 0.7.3 (including) |
Opensuse | Opensuse | 12.3 (including) | 12.3 (including) |
Opensuse | Opensuse | 13.1 (including) | 13.1 (including) |
Eyed3 | Ubuntu | esm-apps/xenial | * |
Eyed3 | Ubuntu | lucid | * |
Eyed3 | Ubuntu | precise | * |
Eyed3 | Ubuntu | quantal | * |
Eyed3 | Ubuntu | saucy | * |
Eyed3 | Ubuntu | trusty | * |
Eyed3 | Ubuntu | upstream | * |
Eyed3 | Ubuntu | utopic | * |
Eyed3 | Ubuntu | vivid | * |
Eyed3 | Ubuntu | wily | * |
Eyed3 | Ubuntu | xenial | * |