yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2007-4460
Component Overview
Vulnerability Overview
Name
CVE-2007-4460
Source
NVD (
link
)
Debian (
link
)
Description
The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.
CWEs
Published Date
Aug 21, 2007
Updated Date
Jun 16, 2026
Workaround
-
Advisories
http://secunia.com/advisories/26536
Vendor Advisory
http://www.securityfocus.com/bid/25372
Exploit
http://secunia.com/advisories/26536
Vendor Advisory
http://www.securityfocus.com/bid/25372
Exploit
Analysis
#
Affected Component
Analysis
id3lib
Patched
Vulnerability Rating
#
7.2
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
id3lib
yocto
kirkstone
3.8.3
Not Affected
id3lib
yocto
master
3.8.3
Patched