The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.
References
Configurations
Information
Published : 2007-08-21 14:17
Updated : 2008-09-05 14:28
NVD link : CVE-2007-4460
Mitre link : CVE-2007-4460
JSON object : View
CWE
Products Affected
id3lib
- id3lib