Your submission was sent successfully! Close

CVE-2007-6061

Published: 20 November 2007

Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.

Priority

Low

Status

Package Release Status
audacity
Launchpad, Ubuntu, Debian
Upstream Needed