PT-2004-2229 · Yamt · Yamt

Publicado

2004-12-22

·

Atualizado

2017-07-11

·

CVE-2004-1302

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: YAMT version 0.5
Description: The issue allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag. This is due to a problem in the id3tag sort function in id3tag.c.
Recommendations: For YAMT version 0.5, consider disabling the id3tag sort function until a patch is available to prevent exploitation. Restrict access to MP3 files with double quotes in the Artist tag to minimize the risk of arbitrary command execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1302

Produtos afetados

Yamt