Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation20 reference(s) from NVD