rhythmbox: code execution
| Package(s): | rhythmbox | CVE #(s): | CVE-2012-3355 | ||||||||||||
| Created: | July 12, 2012 | Updated: | August 6, 2012 | ||||||||||||
| Description: | From the Ubuntu advisory:
Hans Spaans discovered that the Context plugin in Rhythmbox created a temporary directory in an insecure manner. A local attacker could exploit this to execute arbitrary code as the user invoking the program. The Context plugin is disabled by default in Ubuntu. | ||||||||||||||
| Alerts: |
| ||||||||||||||
