CVE-2014-1934

low
Published 2022-05-14 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
3.3

Description

tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

OS impact

suse SUSE Affected 2 releases
VersionStatusFixed in
13.1 Affected โ€”
12.3 Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 0.6.18-3
sid Fixed 0.6.18-3
forky Fixed 0.6.18-3
bullseye Fixed 0.6.18-3
bookworm Fixed 0.6.18-3

Package impact

EcosystemPackageVulnerableFixed
python PyPIeyed3<0.7.50.7.5

Application impact

VendorProductVersionsFixed
travis_shirkeyed3{"endIncluding":"0.6.18"}
travis_shirkeyed30.1.0
travis_shirkeyed30.2.0
travis_shirkeyed30.3.0
travis_shirkeyed30.3.1
travis_shirkeyed30.4.0
travis_shirkeyed30.5.0
travis_shirkeyed30.5.1
travis_shirkeyed30.6.0
travis_shirkeyed30.6.1
travis_shirkeyed30.6.2
travis_shirkeyed30.6.3
travis_shirkeyed30.6.4
travis_shirkeyed30.6.5
travis_shirkeyed30.6.6
travis_shirkeyed30.6.8
travis_shirkeyed30.6.9
travis_shirkeyed30.6.10
travis_shirkeyed30.6.11
travis_shirkeyed30.6.12
travis_shirkeyed30.6.13
travis_shirkeyed30.6.14
travis_shirkeyed30.6.15
travis_shirkeyed30.6.16
travis_shirkeyed30.6.17
travis_shirkeyed30.7.3

References

CWEs

CWE-59

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.