PT-2004-2644 · Music Daemon · Musicd

Tal0N

·

Publicado

2004-08-23

·

Atualizado

2017-07-11

·

CVE-2004-1740

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Music daemon (musicd) versions 0.0.3 and earlier
Description The issue allows remote attackers to read arbitrary files. This is achieved by calling LOAD with a full pathname, then calling SHOWLIST.
Recommendations For Music daemon (musicd) versions 0.0.3 and earlier, consider restricting access to the LOAD and SHOWLIST functions until a patch is available. As a temporary workaround, avoid using the LOAD function with full pathnames to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1740

Produtos afetados

Musicd