SB2007091501 - Gentoo update for id3lib
Published: September 15, 2007 Updated: September 25, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2007-4460)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.
Remediation
Install update from vendor's website.