CVE-2009-0035

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
09/11/2019
Last modified:
21/11/2024

Description

alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:alsa-project:alsa:*:*:*:*:*:*:*:* 1.0.19 (including) 1.0.20 (excluding)