Bug 459135 (CVE-2008-3699) - CVE-2008-3699 amarok: temporary file vulnerability via symlink attacks (priv esc)
Summary: CVE-2008-3699 amarok: temporary file vulnerability via symlink attacks (priv ...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2008-3699
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2008-08-14 16:46 UTC by Jan Lieskovsky
Modified: 2019-09-29 12:26 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2010-12-23 22:32:40 UTC
Embargoed:


Attachments (Terms of Use)

Description Jan Lieskovsky 2008-08-14 16:46:47 UTC
Description of problem:

The "MagnatuneBrowser::listDownloadComplete()" function in Amarok 1.4.9.1 
and prior versions handles temporary files in an insecure manner. This flaw
can be used by a malicious unprivileged user via symlink attack in combination
with a race condition to overwrite arbitrary files with the privileges of the user running the application (potential privilege escalation).


Version-Release number of selected component (if applicable):
1.4.9.1 and prior versions.

How reproducible:
No reproducer

Proposed patch:

http://websvn.kde.org/?view=rev&revision=846626

Public mentions of this issue:

http://secunia.com/advisories/31418/
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494765
http://bugs.gentoo.org/show_bug.cgi?id=234689

Comment 1 Jan Lieskovsky 2008-08-15 08:31:20 UTC
From CVE description:

The MagnatuneBrowser::listDownloadComplete function in
magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows
local users to overwrite arbitrary files via a symlink attack on the
album_info.xml temporary file.

Comment 2 Fedora Update System 2008-09-10 06:33:29 UTC
amarok-1.4.10-1.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2008-09-10 06:36:49 UTC
amarok-1.4.10-1.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.