PT-2005-2184 · Musicmatch · Musicmatch+1
Robert Fly
·
Published
2005-04-18
·
Updated
2016-10-18
·
CVE-2005-1168
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Musicmatch versions 10.00.2047 and earlier
Description
The issue allows remote attackers to overwrite arbitrary files. This is achieved via the
bstrSavePath argument in the DiagCollectionControl.dll component.Recommendations
For Musicmatch versions 10.00.2047 and earlier, consider restricting access to the DiagCollectionControl.dll component until a patch is available. As a temporary workaround, avoid using the
bstrSavePath argument in sensitive operations to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Diagcollectioncontrol.Dll
Musicmatch