PT-2004-2229 · Yamt · Yamt
Publicado
2004-12-22
·
Atualizado
2017-07-11
·
CVE-2004-1302
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
YAMT version 0.5
Description:
The issue allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag. This is due to a problem in the id3tag sort function in id3tag.c.
Recommendations:
For YAMT version 0.5, consider disabling the id3tag sort function until a patch is available to prevent exploitation. Restrict access to MP3 files with double quotes in the Artist tag to minimize the risk of arbitrary command execution.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Yamt