PT-2006-2849 · Beagle · Beagle

Chris Evans

+1

·

Published

2006-04-21

·

Updated

2024-02-13

·

CVE-2006-1865

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Beagle versions prior to 0.2.5
Description The issue allows attackers to execute arbitrary commands via crafted filenames that inject command line arguments when Beagle launches external helper applications while indexing. This is due to an argument injection vulnerability.
Recommendations For versions prior to 0.2.5, update to version 0.2.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of external helper applications or validating filenames to prevent argument injection until a patch is available.

Fix

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2006-1865

Affected Products

Beagle