|
|
Subscribe / Log in / New account

rhythmbox: code execution

Package(s):rhythmbox CVE #(s):CVE-2012-3355
Created:July 12, 2012 Updated:August 6, 2012
Description: From the Ubuntu advisory:

Hans Spaans discovered that the Context plugin in Rhythmbox created a temporary directory in an insecure manner. A local attacker could exploit this to execute arbitrary code as the user invoking the program. The Context plugin is disabled by default in Ubuntu.

Alerts:
Mageia MGASA-2012-0179 rhythmbox 2012-07-24
Ubuntu USN-1503-1 rhythmbox 2012-07-11
openSUSE openSUSE-SU-2012:0954-1 rhythmbox 2012-08-06

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds