PT-2005-3944 · Mpeg Tools · Mpeg-Tools

Spanky

·

Published

2005-09-30

·

Updated

2008-09-05

·

CVE-2005-3115

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions mpeg-tools versions prior to 1.5b-r2
Description The issue allows local users to overwrite arbitrary files via insecure creation of multiple temporary files, including those named ts.stat, ts.mpg, foobar, blockbar, or foobar[NNN].
Recommendations For versions prior to 1.5b-r2, update to version 1.5b-r2 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary file creation process to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3115

Affected Products

Mpeg-Tools