PT-2006-5571 · Roxio · Deja Vu+1
Adriel T. Desautels
·
Published
2006-09-14
·
Updated
2011-03-08
·
CVE-2006-4801
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Deja Vu as used in Roxio Toast Titanium version 7
Description
A race condition issue exists, allowing local users to execute arbitrary code via temporary files, including dejavu manual.rb, which are executed with raised privileges.
Recommendations
For Deja Vu as used in Roxio Toast Titanium version 7, consider restricting access to temporary files, including dejavu manual.rb, to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deja Vu
Toast Titanium