CVE-2020-11867: Low severity audacity vulnerability
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11867?
CVE-2020-11867 has been classified as a medium severity vulnerability due to the improper permission settings allowing unauthorized access to temporary audio files.
How do I fix CVE-2020-11867?
To fix CVE-2020-11867, update Audacity to version 2.4.2 or later, where this vulnerability has been addressed.
Which versions of Audacity are affected by CVE-2020-11867?
Audacity versions up to and including 2.3.3 are affected by CVE-2020-11867.
What types of files are exposed in the CVE-2020-11867 vulnerability?
The CVE-2020-11867 vulnerability exposes temporary audio .au files to any user on the system.
Can CVE-2020-11867 lead to data leakage?
Yes, CVE-2020-11867 can potentially lead to data leakage as any user can read and play the temporary audio files created by Audacity.