aMule: Parameter injection
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 200909-06 / amule |
| Release Date |
September 09, 2009 |
| Latest Revision |
September 09, 2009: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-p2p/amule |
<
2.2.5 |
>=
2.2.5 |
All supported architectures
|
Related bugreports:
#268163
Synopsis
An input validation error in aMule enables remote attackers to pass
arbitrary parameters to a victim's media player.
2.
Impact Information
Background
aMule is an eMule-like client for the eD2k and Kademlia networks,
supporting multiple platforms.
Description
Sam Hocevar discovered that the aMule preview function does not
properly sanitize file names.
Impact
A remote attacker could entice a user to download a file with a
specially crafted file name to inject arbitrary arguments to the
victim's video player.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All aMule users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-p2p/amule-2.2.5"
|
4.
References
|