LWN.net Logo

amule: insufficient input sanitizing

Package(s):amule CVE #(s):CVE-2009-1440
Created:June 23, 2009 Updated:September 9, 2009
Description: From the Debian advisory: Sam Hocevar discovered that amule, a client for the eD2k and Kad networks, does not properly sanitise the filename, when using the preview function. This could lead to the injection of arbitrary commands passed to the video player.
Alerts:
Gentoo 200909-06 2009-09-09
Debian DSA-1821-1 2009-06-22

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds