Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
BID:13167
Info
Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 13167 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1168 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 14 2005 12:00AM |
| Updated: | Jul 12 2009 12:56PM |
| Credit: | Discovered by Hyperdose Security <[email protected]>. |
| Vulnerable: |
Sun ONE Directory Server 5.1 x86 Sun ONE Directory Server 5.1 SP3 x86 Sun ONE Directory Server 5.1 SP3 Sun ONE Directory Server 5.1 SP2 Sun ONE Directory Server 5.1 SP1 Sun ONE Directory Server 5.1 Sun Java System Directory Server 5.2 Musicmatch Inc. Musicmatch Jukebox 10.0.2047 Musicmatch Inc. Musicmatch Jukebox 9.0.5059 |
| Not Vulnerable: | |
Discussion
Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
Musicmatch Jukebox is prone to an arbitrary file overwrite vulnerability through an ActiveX control marked safe for scripting. This could allow a remote attacker to overwrite any file to which the user running Musicmatch has write permissions.
Musicmatch Jukebox is prone to an arbitrary file overwrite vulnerability through an ActiveX control marked safe for scripting. This could allow a remote attacker to overwrite any file to which the user running Musicmatch has write permissions.
Exploit / POC
Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
A proof of concept is available at the following Web page:
http://www.hyperdose.com/exploits/musicmatchFileOverwriteExploit.html
A proof of concept is available at the following Web page:
http://www.hyperdose.com/exploits/musicmatchFileOverwriteExploit.html
Solution / Fix
Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
Solution:
Musicmatch has released new versions of Jukebox that address this issue.
Musicmatch Inc. Musicmatch Jukebox 10.0.2047
Musicmatch Inc. Musicmatch Jukebox 9.0.5059
Solution:
Musicmatch has released new versions of Jukebox that address this issue.
Musicmatch Inc. Musicmatch Jukebox 10.0.2047
-
Musicmatch Jukebox
http://www.musicmatch.com/download/free/security.htm
Musicmatch Inc. Musicmatch Jukebox 9.0.5059
-
Musicmatch Jukebox
http://www.musicmatch.com/download/free/security.htm
References
Musicmatch Jukebox DiagCollectionControl.dll Arbitrary File Overwrite Vulnerability
References:
References:
- Musicmatch Home Page (Musicmatch)
- Security Updates - FAQ (Musicmatch)