CVE-2006-6979
Summary
| CVE | CVE-2006-6979 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-02-08 18:28:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Gentoo update for amarok - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| Amarok Magnature Shell Command Injection Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Gentoo Bug 166901 - media-sound/amarok: remote exec of arbitrary code from a malicious server | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | |
| SuSE Security announcements: [suse-security-announce] SUSE Security Summary Report SUSE-SR:2007:002 | af854a3a-2127-422b-91ae-364da2661108 | lists.suse.com | Vendor Advisory |
| Amarok: User-assisted remote execution of arbitrary code — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Bug 138499 – amarok magnatune unsafe shell | af854a3a-2127-422b-91ae-364da2661108 | bugs.kde.org | Vendor Advisory |
| Amarok Magnatune Shell Command Injection - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SUSE Update for Multiple Packages - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.