Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Gentoo: 200909-06 Normal: aMule Parameter Injection Attack

gentoo
Calendar Grey September 9, 2009
Dist Gentoo Esm H88
Debian Security Advisory 200901-15 highlights VLC media player vulnerabilities that could enable unauthorized access to user data. Immediate patching advised.
An input validation error in aMule enables remote attackers to pass arbitrary parameters to a victim's media player.

Summary

Gentoo Linux Security Advisory GLSA 200909-06 https://security.gentoo.org/ Severity: Normal Title: aMule: Parameter injection Date: September 09, 2009 Bugs: #268163 ID: 200909-06

Synopsis ======= An input validation error in aMule enables remote attackers to pass arbitrary parameters to a victim's media player.
Background ========= aMule is an eMule-like client for the eD2k and Kademlia networks, supporting multiple platforms.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-p2p/amule < 2.2.5 >= 2.2.5
========== Sam Hocevar discovered that the aMule preview function does not properly sanitize file names.
Impact ===== A remote attacker could entice...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/69932_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here