Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Gentoo: 200909-06 Normal: aMule Parameter Injection Attack

gentoo
Calendar Grey September 9, 2009
Scroller Gentoo
Debian Security Advisory 200901-15 highlights VLC media player vulnerabilities that could enable unauthorized access to user data. Immediate patching advised.
An input validation error in aMule enables remote attackers to pass arbitrary parameters to a victim's media player.

Summary

Gentoo Linux Security Advisory GLSA 200909-06 https://security.gentoo.org/ Severity: Normal Title: aMule: Parameter injection Date: September 09, 2009 Bugs: #268163 ID: 200909-06

Synopsis ======= An input validation error in aMule enables remote attackers to pass arbitrary parameters to a victim's media player.
Background ========= aMule is an eMule-like client for the eD2k and Kademlia networks, supporting multiple platforms.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-p2p/amule < 2.2.5 >= 2.2.5
========== Sam Hocevar discovered that the aMule preview function does not properly sanitize file names.
Impact ===== A remote attacker could entice...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround