Lucene search

K
kasperskyKaspersky LabKLA10407
HistoryFeb 06, 2008 - 12:00 a.m.

KLA10407 ACE vulnerability in Yahoo! Music Jukebox

2008-02-0600:00:00
Kaspersky Lab
threats.kaspersky.com
14

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.7 High

AI Score

Confidence

Low

0.204 Low

EPSS

Percentile

96.4%

Buffer overflows were found in Yahoo! Music Jukebox. By exploiting these vulnerabilities malicious users can execute arbitrary code. This vulnerability can be exploited remotely via specially designed arguments to different methods.

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Related products

Yahoo!-Music-Jukebox

CVE list

CVE-2008-0623 warning

Solution

Update to latest version

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

Affected Products

  • Yahoo! Music Jukebox version 2.2.2.056

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

7.7 High

AI Score

Confidence

Low

0.204 Low

EPSS

Percentile

96.4%