Lucene search

K
osvGoogleOSV:DSA-681-1
HistoryFeb 14, 2005 - 12:00 a.m.

synaesthesia - privilege escalation

2005-02-1400:00:00
Google
osv.dev
7

EPSS

0

Percentile

5.1%

Erik SjĂślund and Devin Carraway discovered that synaesthesia, a
program for representing sounds visually, accesses user-controlled
configuration and mixer files with elevated privileges. Thus, it is
possible to read arbitrary files.

For the stable distribution (woody) this problem has been fixed in
version 2.1-2.1woody3.

For the testing (sarge) and unstable (sid) distribution this problem
does not exist since synaesthesia is not installed setuid root
anymore.

We recommend that you upgrade your synaesthesia package.