PT-2005-1817 · Limewire · Limewire

Kevin Walsh

·

Published

2005-03-14

·

Updated

2017-07-11

·

CVE-2005-0788

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions LimeWire versions 4.1.2 through 4.5.6
Description The issue allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutella GET request.
Recommendations For LimeWire versions 4.1.2 through 4.5.6, consider restricting access to the Gnutella protocol until a patch is available. As a temporary workaround, avoid using the full pathname in Gnutella GET requests to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0788

Affected Products

Limewire