CVE-2007-4460

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2007
Last modified:
09/04/2025

Description

The RenderV2ToFile function in tag_file.cpp in id3lib (aka libid3) 3.8.3 allows local users to overwrite arbitrary files via a symlink attack on a temporary file whose name is constructed from the name of a file being tagged.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:id3lib:id3lib:3.8.3:*:*:*:*:*:*:*