Vulnerabilities > CVE-2004-0160 - Unspecified vulnerability in Synaesthesia

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
synaesthesia
nessus

Summary

Synaesthesia 2.2 and earlier allows local users to execute arbitrary code via a symlink attack on the configuration file.

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-446.NASL
descriptionUlf Harnhammar from the Debian Security Audit Project discovered a vulnerability in synaesthesia, a program which represents sounds visually. synaesthesia created its configuration file while holding root privileges, allowing a local user to create files owned by root and writable by the user
last seen2020-06-01
modified2020-06-02
plugin id15283
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15283
titleDebian DSA-446-1 : synaesthesia - insecure file creation