Music Daemon LOAD Command File Disclosure Vulnerability
BID:11006
Info
Music Daemon LOAD Command File Disclosure Vulnerability
| Bugtraq ID: | 11006 |
| Class: | Access Validation Error |
| CVE: |
CVE-2004-1741 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 23 2004 12:00AM |
| Updated: | Jul 12 2009 06:17AM |
| Credit: | Discovery of this vulnerability is credited to Tal0n <[email protected]>. |
| Vulnerable: |
Music daemon Music daemon 0.3 Music daemon Music daemon 0.2 Music daemon Music daemon 0.1 |
| Not Vulnerable: | |
Discussion
Music Daemon LOAD Command File Disclosure Vulnerability
Music daemon is reported prone to a remote file disclosure vulnerability. The vulnerability presents itself due to a lack of sufficient sanitization performed on Music daemon command arguments.
A remote attacker may exploit this vulnerability in order to disclose the contents of files with the privilege of the Music daemon (musicd) process.
It is reported that if a binary file is specified as an argument for the affected command the attacker may cause the affected daemon to crash.
Music daemon is reported prone to a remote file disclosure vulnerability. The vulnerability presents itself due to a lack of sufficient sanitization performed on Music daemon command arguments.
A remote attacker may exploit this vulnerability in order to disclose the contents of files with the privilege of the Music daemon (musicd) process.
It is reported that if a binary file is specified as an argument for the affected command the attacker may cause the affected daemon to crash.
Exploit / POC
Music Daemon LOAD Command File Disclosure Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Music Daemon LOAD Command File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Music Daemon LOAD Command File Disclosure Vulnerability
References:
References:
- Music daemon Homepage (Music daemon)
- MusicDaemon <= 0.0.3 /etc/shadow Stealer / DoS Exploit (Tal0n
)