PT-2020-6975 · Audacity+5 · Audacity+5

Mike Salvatore

·

Published

2020-05-31

·

Updated

2025-01-16

·

CVE-2020-11867

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Audacity versions 2.3.3 and earlier
Description The issue is related to the default permission settings in Audacity. When Audacity creates temporary files, it saves them to /var/tmp/audacity-$USER and sets the permissions to 755. This allows any user on the system to read and play the temporary audio .au files located there. The vulnerability may allow an attacker to access confidential data.
Recommendations For Audacity versions 2.3.3 and earlier, consider changing the default temporary directory permissions to restrict access to sensitive audio files. As a temporary workaround, restrict access to the /var/tmp/audacity-$USER directory to minimize the risk of exploitation. Update to a version later than 2.3.3 to fully resolve the issue.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2051
ALT-PU-2024-16850
BDU:2024-06966
CVE-2020-11867
MGASA-2021-0001
OPENSUSE-SU-2020:2261-1
OPENSUSE-SU-2020_2261-1
USN-7211-1

Affected Products

Alt Linux
Astra Linux
Audacity
Linuxmint
Suse
Ubuntu