Vulnerabilities > CVE-2007-4460 - Unspecified vulnerability in Id3Lib 3.8.3

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
id3lib
nessus

Summary

The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.

Vulnerable Configurations

Part Description Count
Application
Id3Lib
1

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_15EC9123706111DCB372001921AB2FA4.NASL
    descriptionDebian Bug report log reports : When tagging file $foo, a temporary copy of the file is created, and for some reason, libid3 doesn
    last seen2020-06-01
    modified2020-06-02
    plugin id26212
    published2007-10-03
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/26212
    titleFreeBSD : id3lib -- insecure temporary file creation (15ec9123-7061-11dc-b372-001921ab2fa4)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2007-1774.NASL
    descriptionThis security update fixes a (minor) tempfile creation security issue (CVE-2007-4460) by using mkstemp (bugzilla 253553) Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id27732
    published2007-11-06
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/27732
    titleFedora 7 : id3lib-3.8.3-17.fc7 (2007-1774)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_ID3LIB-4317.NASL
    descriptionThis update fixes a bug that allows local attackers to overwrite arbitrary files. (CVE-2007-4460)
    last seen2020-06-01
    modified2020-06-02
    plugin id29462
    published2007-12-13
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/29462
    titleSuSE 10 Security Update : id3lib (ZYPP Patch Number 4317)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-1365.NASL
    descriptionNikolaus Schulz discovered that a programming error in id3lib, an ID3 Tag Library, may lead to denial of service through symlink attacks.
    last seen2020-06-01
    modified2020-06-02
    plugin id25965
    published2007-09-03
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/25965
    titleDebian DSA-1365-3 : id3lib3.8.3 - programming error
  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2007-180.NASL
    descriptionA programming error was found in id3lib by Nikolaus Schulz that could lead to a denial of service through symlink attacks. Updated packages have been patched to prevent these issues.
    last seen2020-06-01
    modified2020-06-02
    plugin id26047
    published2007-09-14
    reporterThis script is Copyright (C) 2007-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/26047
    titleMandrake Linux Security Advisory : id3lib (MDKSA-2007:180)
  • NASL familySuSE Local Security Checks
    NASL idSUSE9_11786.NASL
    descriptionThis update fixes a bug that allows local attackers to overwrite arbitrary files. (CVE-2007-4460)
    last seen2020-06-01
    modified2020-06-02
    plugin id41150
    published2009-09-24
    reporterThis script is Copyright (C) 2009-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/41150
    titleSuSE9 Security Update : id3lib (YOU Patch Number 11786)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_ID3LIB-4316.NASL
    descriptionThis update fixes a bug that allows local attackers to overwrite arbitrary files. (CVE-2007-4460)
    last seen2020-06-01
    modified2020-06-02
    plugin id27269
    published2007-10-17
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/27269
    titleopenSUSE 10 Security Update : id3lib (id3lib-4316)
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS11_GNOME_20130924.NASL
    descriptionThe remote Solaris system is missing necessary patches to address security updates : - The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged. (CVE-2007-4460) - poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an
    last seen2020-06-01
    modified2020-06-02
    plugin id80625
    published2015-01-19
    reporterThis script is Copyright (C) 2015-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/80625
    titleOracle Solaris Third-Party Patch Update : gnome (cve_2007_4460_symlink_attack)
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-200709-08.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-200709-08 (id3lib: Insecure temporary file creation) Nikolaus Schulz discovered that the function RenderV2ToFile() in file src/tag_file.cpp creates temporary files in an insecure manner. Impact : A local attacker could exploit this vulnerability via a symlink attack to overwrite arbitrary files. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id26098
    published2007-09-24
    reporterThis script is Copyright (C) 2007-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/26098
    titleGLSA-200709-08 : id3lib: Insecure temporary file creation