Code Injection in Rhythmbox - CVE-2012-3355

 

Code Injection in Rhythmbox - CVE-2012-3355

Published: July 18, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU43849
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-3355
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.

(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.


Affected software

Rhythmbox

How to mitigate CVE-2012-3355

Install update from vendor's website.


External References

Related Security Bulletins