PT-2014-4373 · Python · Eyed3

Published

2014-05-08

·

Updated

2024-06-15

·

CVE-2014-1934

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions eyeD3 (aka python-eyed3) versions 0.7.5 and earlier eyeD3 (aka python-eyed3) version 7.0.3 eyeD3 (aka python-eyed3) version 0.6.18
Description The issue allows local users to modify arbitrary files via a symlink attack on a temporary file. This is related to the tag.py component in eyeD3.
Recommendations For eyeD3 (aka python-eyed3) versions 0.7.5 and earlier, update to a version later than 0.7.5 to resolve the issue. For eyeD3 (aka python-eyed3) version 7.0.3, update to a version later than 7.0.3 to resolve the issue. For eyeD3 (aka python-eyed3) version 0.6.18, update to a version later than 0.6.18 to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-1934
GHSA-4R2W-W73W-36JM
OPENSUSE-SU-2024:10474-1

Affected Products

Eyed3