First published: Tue Nov 20 2007(Updated: )
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Audacity | =1.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6061 is considered a medium severity vulnerability due to its ability to cause a denial of service.
To fix CVE-2007-6061, ensure that Audacity is upgraded to a newer version that addresses this issue.
CVE-2007-6061 affects users running Audacity version 1.3.2.
CVE-2007-6061 allows local users to perform a denial of service attack by creating a directory before Audacity is executed.
While CVE-2007-6061 was reported in 2007, using outdated software versions can still expose systems to this vulnerability.