PT-2004-2203 · Greed · Greed
Published
2004-12-22
·
Updated
2017-07-11
·
CVE-2004-1274
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
greed version 0.81p
Description:
The issue allows remote attackers to execute arbitrary code via a GRX file containing a filename with shell metacharacters, specifically through the DownloadLoop function in main.c.
Recommendations:
For greed version 0.81p, consider disabling the DownloadLoop function in main.c to prevent exploitation until a patch is available. Restrict access to GRX files to minimize the risk of arbitrary code execution.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Greed