YAMT ID3 Tag Sort Command Execution Vulnerability
BID:11999
Info
YAMT ID3 Tag Sort Command Execution Vulnerability
| Bugtraq ID: | 11999 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-1302 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2004 12:00AM |
| Updated: | Jul 12 2009 09:26AM |
| Credit: | Discovery is credited to Manigandan Radhakrishnan. |
| Vulnerable: |
YAMT YAMT 0.5 |
| Not Vulnerable: | |
Discussion
YAMT ID3 Tag Sort Command Execution Vulnerability
YAMT (Yet Another MP3 Tool) is prone to a vulnerability that may allow attackers to execute arbitrary commands. This issue is exposed when the program attempts to sort ID3 tags. As this data may originate from an external or untrusted source, this issue is considered remote in nature.
Successful exploitation will allow an attacker to execute arbitrary commands when the software processes an MP3 that contains malicious ID3 tag data. This will occur in the context of the user running the application.
YAMT (Yet Another MP3 Tool) is prone to a vulnerability that may allow attackers to execute arbitrary commands. This issue is exposed when the program attempts to sort ID3 tags. As this data may originate from an external or untrusted source, this issue is considered remote in nature.
Successful exploitation will allow an attacker to execute arbitrary commands when the software processes an MP3 that contains malicious ID3 tag data. This will occur in the context of the user running the application.
Exploit / POC
YAMT ID3 Tag Sort Command Execution Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
YAMT ID3 Tag Sort Command Execution Vulnerability
Solution:
YAMT is no longer maintained so it is not believed that the vendor will provide fixes for this vulnerability. Affected users may wish to migrate to an application that is actively maintained.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
YAMT is no longer maintained so it is not believed that the vendor will provide fixes for this vulnerability. Affected users may wish to migrate to an application that is actively maintained.
---
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
YAMT ID3 Tag Sort Command Execution Vulnerability
References:
References:
- [remote] [control] YAMT 0.5 id3tag_sort does not check for nasty characters ("D. J. Bernstein"
) - YAMT Homepage (YAMT)