CVE-2014-0027
Publication date 26 January 2014
Last updated 22 May 2026
Ubuntu priority
Description
The play_wave_from_socket function in audio/auserver.c in Flite 1.4 allows local users to modify arbitrary files via a symlink attack on /tmp/awb.wav. NOTE: some of these details are obtained from third party information.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| flite | ||
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
|
Notes
mdeslaur
not only does Yama protect the temp file against misuse, but the Debian bug states that nothing in the archive uses the insecure function.