Upstream information
Description
(1) AlbumTab.py, (2) ArtistTab.py, (3) LinksTab.py, and (4) LyricsTab.py in the Context module in GNOME Rhythmbox 0.13.3 and earlier allows local users to execute arbitrary code via a symlink attack on a temporary HTML template file in the /tmp/context directory.SUSE information
Overall state of this security issue: Resolved
This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.
National Vulnerability Database | |
---|---|
Base Score | 3.6 |
Vector | AV:L/AC:L/Au:N/C:N/I:P/A:P |
Access Vector | Local |
Access Complexity | Low |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | Partial |
SUSE Security Advisories:
- openSUSE-SU-2012:0954-1
List of released packages
Product(s) | Fixed package version(s) | References |
---|---|---|
SUSE Linux Enterprise Desktop 12 SP1 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP1 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Software Development Kit 12 SP1 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Workstation Extension 12 SP1 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Desktop 12 SP2 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP2 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Software Development Kit 12 SP2 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP2 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Desktop 12 SP3 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP3 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Software Development Kit 12 SP3 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP3 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Desktop 12 SP4 |
| Patchnames: SUSE Linux Enterprise Desktop 12 SP4 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Software Development Kit 12 SP4 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP4 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Desktop 12 |
| Patchnames: SUSE Linux Enterprise Desktop 12 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Software Development Kit 12 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Workstation Extension 12 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server for SAP Applications 12 SP1 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP1 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Workstation Extension 12 SP1 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server for SAP Applications 12 SP2 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP2 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP2 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server for SAP Applications 12 SP3 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP3 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP3 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Server 12 SP4 SUSE Linux Enterprise Server for SAP Applications 12 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP4 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP4 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server for SAP Applications 12 SP5 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP5 GA rhythmbox-3.4-6.14 SUSE Linux Enterprise Workstation Extension 12 SP5 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server for SAP Applications 12 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 GA rhythmbox-3.0.2-1.92 SUSE Linux Enterprise Workstation Extension 12 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Software Development Kit 12 SP1 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP1 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Software Development Kit 12 SP2 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP2 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Software Development Kit 12 SP3 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP3 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Software Development Kit 12 SP4 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP4 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Software Development Kit 12 SP5 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 SP5 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Software Development Kit 12 |
| Patchnames: SUSE Linux Enterprise Software Development Kit 12 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Workstation Extension 12 SP1 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP1 GA rhythmbox-3.0.2-1.92 |
SUSE Linux Enterprise Workstation Extension 12 SP2 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP2 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Workstation Extension 12 SP3 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP3 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Workstation Extension 12 SP4 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP4 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Workstation Extension 12 SP5 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 SP5 GA rhythmbox-3.4-6.14 |
SUSE Linux Enterprise Workstation Extension 12 |
| Patchnames: SUSE Linux Enterprise Workstation Extension 12 GA rhythmbox-3.0.2-1.92 |
openSUSE Tumbleweed |
| Patchnames: openSUSE-Tumbleweed-2024-10321 |
SUSE Timeline for this CVE
CVE page created: Fri Jun 28 12:54:22 2013CVE page last modified: Sat Jun 15 21:37:56 2024