Executive Summary

Summary
Title Amarok vulnerability
Informations
NameUSN-657-1First vendor Publication2008-10-21
VendorUbuntuLast vendor Modification2008-10-21
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:M/Au:N/C:N/I:P/A:P)
Cvss Base Score3.3Attack RangeLocal
Cvss Impact Score4.9Attack ComplexityMedium
Cvss Expoit Score3.4AuthentificationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects the following Ubuntu releases:

Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 7.10:
amarok 2:1.4.7-0ubuntu3.1

Ubuntu 8.04 LTS:
amarok 2:1.4.9.1-0ubuntu3.1

After a standard system upgrade you need to restart Amarok to effect
the necessary changes.

Details follow:

Dwayne Litzenberger discovered that Amarok created temporary files in
an insecure way. Local users could exploit a race condition to create
or overwrite files with the privileges of the user invoking the
program. (CVE-2008-3699)


Original Source

Url : http://www.ubuntu.com/usn/USN-657-1

CWE : Common Weakness Enumeration

idName
CWE-59Improper Link Resolution Before File Access ('Link Following')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application1

Open Source Vulnerability Database (OSVDB)

idDescription
47455Amarok magnatunebrowser/magnatunebrowser.cpp MagnatuneBrowser::listDownloadCo...