Lucene search

K
freebsdFreeBSDD4A7054A-6D96-11D9-A9E7-0001020EED82
HistoryDec 15, 2004 - 12:00 a.m.

yamt -- arbitrary command execution vulnerability

2004-12-1500:00:00
vuxml.freebsd.org
12

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.048 Low

EPSS

Percentile

92.7%

Manigandan Radhakrishnan discovered a security
vulnerability in YAMT which can lead to execution of
arbitrary commands with the privileges of the user running
YAMT when sorting based on MP3 tags. The problem exist in
the id3tag_sort() routine which does not
properly sanitize the artist tag from the MP3 file before
using it as an argument to the mv command.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchyamt< 0.5_2UNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.048 Low

EPSS

Percentile

92.7%

Related for D4A7054A-6D96-11D9-A9E7-0001020EED82