The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rawstudio | Rawstudio | 2.0-1.1 (including) | 2.0-1.1 (including) |
Rawstudio | Ubuntu | lucid | * |
Rawstudio | Ubuntu | precise | * |
Rawstudio | Ubuntu | trusty | * |