Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Kevin Walsh

#22292de 53,635
10CVSS total
Vulnerabilidades · 2
Média
2
PT-2005-1817
5.0
2005-03-14
Limewire · Limewire · CVE-2005-0788
**Name of the Vulnerable Software and Affected Versions** LimeWire versions 4.1.2 through 4.5.6 **Description** The issue allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request. **Recommendations** For LimeWire versions 4.1.2 through 4.5.6, consider restricting access to the Gnutella protocol until a patch is available. As a temporary workaround, avoid using the full pathname in Gnutella GET requests to minimize the risk of exploitation.
PT-2005-1818
5.0
2005-03-14
Limewire · Limewire · CVE-2005-0789
**Name of the Vulnerable Software and Affected Versions** LimeWire versions 3.9.6 through 4.6.0 **Description** A directory traversal issue allows remote attackers to read arbitrary files by including a .. (dot dot) in a magnet request. **Recommendations** For LimeWire versions 3.9.6 through 4.6.0, consider restricting access to magnet requests until a patch is available. As a temporary workaround, avoid using the .. (dot dot) sequence in magnet requests to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.