| Vulnerability Name: | CVE-2009-1440 (CCN-50205) | ||||||||||||||||
| Assigned: | 2009-04-22 | ||||||||||||||||
| Published: | 2009-04-22 | ||||||||||||||||
| Updated: | 2017-08-17 | ||||||||||||||||
| Summary: | Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename. | ||||||||||||||||
| CVSS v3 Severity: | 5.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.5 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||
| References: | Source: CCN Type: Debian Bug report logs - #525078 insufficient path escaping when opening fies Source: MISC Type: Exploit http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=525078 Source: MITRE Type: CNA CVE-2009-1440 Source: CCN Type: SA34839 aMule Video Preview Arbitrary Parameter Injection Security Issue Source: SECUNIA Type: UNKNOWN 34839 Source: CCN Type: aMule Web site Welcome to aMule, the all-platform eMule-like P2P client Source: DEBIAN Type: UNKNOWN DSA-1821 Source: DEBIAN Type: DSA-1821 amule -- insufficient input sanitising Source: CCN Type: GLSA-200909-06 aMule: Parameter injection Source: MLIST Type: UNKNOWN [oss-security] 20090422 CVE id request: amule Source: CCN Type: OSVDB ID: 54179 aMule mplayer Video Preview Filename Arbitrary Parameter Injection Source: BID Type: UNKNOWN 34683 Source: CCN Type: BID-34683 aMule 'wxExecute()' Arbitrary Command Execution Vulnerability Source: XF Type: UNKNOWN amule-downloadlistctrl-command-execution(50205) Source: XF Type: UNKNOWN amule-downloadlistctrl-command-execution(50205) | ||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
| Oval Definitions | |||||||||||||||||
| |||||||||||||||||
| BACK | |||||||||||||||||