Lucene search

K
ubuntuUbuntuUSN-657-1
HistoryOct 21, 2008 - 12:00 a.m.

Amarok vulnerability

2008-10-2100:00:00
ubuntu.com
27

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.1%

Releases

  • Ubuntu 8.04
  • Ubuntu 7.10

Packages

  • amarok -

Details

Dwayne Litzenberger discovered that Amarok created temporary files in
an insecure way. Local users could exploit a race condition to create
or overwrite files with the privileges of the user invoking the
program. (CVE-2008-3699)

OSVersionArchitecturePackageVersionFilename
Ubuntu8.04noarchamarok< 2:1.4.9.1-0ubuntu3.1UNKNOWN
Ubuntu8.04noarchamarok-engines< 2:1.4.9.1-0ubuntu3.1UNKNOWN
Ubuntu8.04noarchamarok-xine< 2:1.4.9.1-0ubuntu3.1UNKNOWN
Ubuntu7.10noarchamarok< 2:1.4.7-0ubuntu3.1UNKNOWN
Ubuntu7.10noarchamarok< engines-2:1.4.7-0ubuntu3.1UNKNOWN
Ubuntu7.10noarchamarok< xine-2:1.4.7-0ubuntu3.1UNKNOWN

3.3 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.1%