{"api_version":"1","generated_at":"2026-07-23T07:39:00+00:00","cve":"CVE-2006-6979","urls":{"html":"https://cve.report/CVE-2006-6979","api":"https://cve.report/api/cve/CVE-2006-6979.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6979","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6979"},"summary":{"title":"CVE-2006-6979","description":"The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-02-08 18:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/24510","name":"http://secunia.com/advisories/24510","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Gentoo update for amarok - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0613","name":"http://www.vupen.com/english/advisories/2007/0613","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/22568","name":"http://www.securityfocus.com/bid/22568","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Amarok Magnature Shell Command Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=166901","name":"http://bugs.gentoo.org/show_bug.cgi?id=166901","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Bug 166901 - media-sound/amarok: remote exec of arbitrary code from a malicious server","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html","name":"http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SuSE Security announcements: [suse-security-announce] SUSE Security Summary Report SUSE-SR:2007:002","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200703-11.xml","name":"http://security.gentoo.org/glsa/glsa-200703-11.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Amarok: User-assisted remote execution of arbitrary code — Gentoo Linux Documentation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.kde.org/show_bug.cgi?id=138499","name":"http://bugs.kde.org/show_bug.cgi?id=138499","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Bug 138499 – amarok magnatune unsafe shell","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/24159","name":"http://secunia.com/advisories/24159","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Amarok Magnatune Shell Command Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23984","name":"http://secunia.com/advisories/23984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6979","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6979","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6979","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"amarok","cpe5":"amarok","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:50:04.608Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23984","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23984"},{"name":"ADV-2007-0613","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0613"},{"name":"SUSE-SR:2007:002","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=166901"},{"name":"24510","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24510"},{"name":"22568","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22568"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.kde.org/show_bug.cgi?id=138499"},{"name":"GLSA-200703-11","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200703-11.xml"},{"name":"24159","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24159"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-27T00:00:00.000Z","descriptions":[{"lang":"en","value":"The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-02-16T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23984","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23984"},{"name":"ADV-2007-0613","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0613"},{"name":"SUSE-SR:2007:002","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html"},{"tags":["x_refsource_MISC"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=166901"},{"name":"24510","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24510"},{"name":"22568","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22568"},{"tags":["x_refsource_MISC"],"url":"http://bugs.kde.org/show_bug.cgi?id=138499"},{"name":"GLSA-200703-11","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200703-11.xml"},{"name":"24159","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24159"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6979","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23984","refsource":"SECUNIA","url":"http://secunia.com/advisories/23984"},{"name":"ADV-2007-0613","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0613"},{"name":"SUSE-SR:2007:002","refsource":"SUSE","url":"http://lists.suse.com/archive/suse-security-announce/2007-Jan/0015.html"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=166901","refsource":"MISC","url":"http://bugs.gentoo.org/show_bug.cgi?id=166901"},{"name":"24510","refsource":"SECUNIA","url":"http://secunia.com/advisories/24510"},{"name":"22568","refsource":"BID","url":"http://www.securityfocus.com/bid/22568"},{"name":"http://bugs.kde.org/show_bug.cgi?id=138499","refsource":"MISC","url":"http://bugs.kde.org/show_bug.cgi?id=138499"},{"name":"GLSA-200703-11","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200703-11.xml"},{"name":"24159","refsource":"SECUNIA","url":"http://secunia.com/advisories/24159"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6979","datePublished":"2007-02-08T18:00:00.000Z","dateReserved":"2007-02-08T00:00:00.000Z","dateUpdated":"2024-08-07T20:50:04.608Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-02-08 18:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:amarok:amarok:*:*:*:*:*:*:*:*","matchCriteriaId":"E570741F-43B4-4D13-A84E-8DE0E59436A4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6979","Ordinal":"1","Title":"CVE-2006-6979","CVE":"CVE-2006-6979","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6979","Ordinal":"1","NoteData":"The ruby handlers in the Magnatune component in Amarok do not properly quote text in certain contexts, probably including construction of an unzip command line, which allows attackers to execute arbitrary commands via shell metacharacters.","Type":"Description","Title":"CVE-2006-6979"},{"CveYear":"2006","CveId":"6979","Ordinal":"2","NoteData":"2007-02-08","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6979","Ordinal":"3","NoteData":"2007-02-16","Type":"Other","Title":"Modified"}]}}}