PT-2009-3941 · Amule Team+1 · Amule+1

Nico Golde

·

Published

2009-04-27

·

Updated

2017-08-17

·

CVE-2009-1440

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions amule version 2.2.4
Description The issue allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename, due to an incomplete blacklist vulnerability in DownloadListCtrl.cpp.
Recommendations For amule version 2.2.4, update to a version that fixes the incomplete blacklist vulnerability in DownloadListCtrl.cpp to prevent argument injection attacks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2009-1440
DSA-1821-1

Affected Products

Amule
Mplayer