Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200909-06
https://security.gentoo.org/
Severity: Normal
Title: aMule: Parameter injection
Date: September 09, 2009
Bugs: #268163
ID: 200909-06
Synopsis
=======
An input validation error in aMule enables remote attackers to pass
arbitrary parameters to a victim's media player.
Background
=========
aMule is an eMule-like client for the eD2k and Kademlia networks,
supporting multiple platforms.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-p2p/amule < 2.2.5 >= 2.2.5
==========
Sam Hocevar discovered that the aMule preview function does not
properly sanitize file names.
Impact
=====
A remote attacker could entice...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.