Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jonathan Neuschäfer

#15452of 53,633
17.5Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2018-18924
7.5
2018-04-03
Music Player Daemon · Ncmpc · CVE-2018-9240
**Name of the Vulnerable Software and Affected Versions** ncmpc versions prior to 0.30 **Description** The issue is related to a NULL pointer dereference flaw. If a user is using the chat screen and another client sends a long chat message, it could cause a crash and denial of service. **Recommendations** For versions prior to 0.30, update to version 0.30 or later to resolve the issue.
PT-2017-3353
10
2017-11-21
Ohcount · Ohcount · CVE-2017-16926
**Name of the Vulnerable Software and Affected Versions** Ohcount version 3.0.0 **Description** The issue is related to a lack of input data sanitization, which can be exploited by an attacker providing a source tree for Ohcount processing to execute arbitrary code as the user running Ohcount. This can be achieved through specially crafted filenames containing shell metacharacters. **Recommendations** For Ohcount version 3.0.0, consider validating and sanitizing filenames before processing to prevent command injection attacks. As a temporary workaround, restrict the use of Ohcount to trusted sources and avoid using it with unverified input data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.