PT-2009-3941 · Amule Team+1 · Amule+1
Nico Golde
·
Published
2009-04-27
·
Updated
2017-08-17
·
CVE-2009-1440
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
amule version 2.2.4
Description
The issue allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename, due to an incomplete blacklist vulnerability in DownloadListCtrl.cpp.
Recommendations
For amule version 2.2.4, update to a version that fixes the incomplete blacklist vulnerability in DownloadListCtrl.cpp to prevent argument injection attacks.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Amule
Mplayer