LiveActive security incident?Get immediate response
CVE Record

CVE-2020-11867: Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default.

Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

Audacity through 2.3.3 could leave temporary audio files readable by other local users. The business risk is unintended disclosure of recorded or edited audio on shared systems, not remote compromise. Exposure is most relevant on multi-user Linux or Unix-like workstations where sensitive audio is handled.

Executive priority

Treat this as a targeted confidentiality issue. Prioritize shared machines, production audio workflows, legal, healthcare, customer-support, or investigative recordings. Broad emergency response is not supported by the provided evidence.

Technical view

The CVE states Audacity created /var/tmp/audacity-$USER by default, then set permissions to 755. That made temporary .au audio files readable by any local user. The source bundle provides no CVSS score, CWE, confirmed fixed version, or evidence of active exploitation.

Likely exposure

Likely exposure is limited to Audacity through 2.3.3 on systems with local multi-user access. Single-user desktops have lower practical risk, while shared workstations handling confidential recordings have higher confidentiality impact.

Exploitation context

CISA KEV status is false, and the provided sources do not report active exploitation. The issue is locally exploitable after Audacity creates temporary audio files; it does not indicate remote access, privilege escalation, or code execution.

Researcher notes

The record lacks CVSS, CWE, and an explicit fixed version. Analysis should focus on local file permissions and temporary-file handling. Do not assume broader Audacity versions, platforms, or exploit activity beyond the cited record.

Mitigation direction

  • Update Audacity using official releases or trusted distribution packages.
  • Review Fedora advisories if managing Fedora-packaged Audacity installations.
  • Check vendor or distribution notes for the exact fixed package version.
  • Avoid editing sensitive audio on affected shared systems.
  • Remove residual Audacity temporary audio files after validation.

Validation and detection

  • Inventory systems running Audacity through version 2.3.3.
  • Identify shared systems where multiple local users can log in.
  • Check whether Audacity temporary audio files exist under /var/tmp/audacity-$USER.
  • Verify updated packages no longer expose temporary audio to other users.
  • Confirm cleanup of leftover temporary audio files on affected hosts.
Prepared
Confidence
high
Sources
6

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-11867 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
5Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.