|
|
| |
|
| |
rhythmbox: code execution
| Package(s): | rhythmbox |
CVE #(s): | CVE-2012-3355
|
| Created: | July 12, 2012 |
Updated: | August 6, 2012 |
| Description: |
From the Ubuntu advisory:
Hans Spaans discovered that the Context plugin in Rhythmbox created a
temporary directory in an insecure manner. A local attacker could exploit
this to execute arbitrary code as the user invoking the program. The
Context plugin is disabled by default in Ubuntu. |
| Alerts: |
|
( Log in to post comments)
|
|
|