SB2012071804 - Code Injection in Rhythmbox
Published: July 18, 2012 Updated: August 11, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Code Injection (CVE-ID: CVE-2012-3355)
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.
Remediation
Install update from vendor's website.
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=616673
- http://people.canonical.com/~ubuntu-security/cve/2012/CVE-2012-3355.html
- http://www.openwall.com/lists/oss-security/2012/06/25/5
- http://www.openwall.com/lists/oss-security/2012/06/25/7
- http://www.securityfocus.com/bid/54186
- http://www.ubuntu.com/usn/USN-1503-1
- https://bugzilla.gnome.org/show_bug.cgi?id=678661
- https://bugzilla.redhat.com/show_bug.cgi?id=835076
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76538
- https://hermes.opensuse.org/messages/15351848