
DescriptionThe MagnatuneBrowser::listDownloadComplete function in magnatunebrowser/magnatunebrowser.cpp in Amarok before 1.4.10 allows local users to overwrite arbitrary files via a symlink attack on the album_info.xml temporary file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs494765

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
amarok (PTS)jessie2.8.0-2.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
amaroksourceetch(not affected)


The code in question doesn't dereference the symlink, tested with Etch
and Lenny. Given that it only takes a minute to test this, it's surprising
that at least one vendor issued an advisory and upstream pushed a new release...

