Multiple Vendor lpCommandLine Application Path Vulnerability
BID:15448
Info
Multiple Vendor lpCommandLine Application Path Vulnerability
| Bugtraq ID: | 15448 |
| Class: | Design Error |
| CVE: |
CVE-2005-2937 CVE-2005-2936 CVE-2005-2939 CVE-2005-2940 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 16 2005 12:00AM |
| Updated: | Jul 12 2009 05:56PM |
| Credit: | Discovery is credited to an anonymous source. |
| Vulnerable: |
VMWare Workstation 5.0 .0 build-13124 RealNetworks RealPlayer 8 RealNetworks RealPlayer 10.5 v6.0.12.1348 RealNetworks RealPlayer 10.5 v6.0.12.1235 RealNetworks RealPlayer 10.5 v6.0.12.1069 RealNetworks RealPlayer 10.5 v6.0.12.1059 RealNetworks RealPlayer 10.5 v6.0.12.1056 RealNetworks RealPlayer 10.5 v6.0.12.1053 RealNetworks RealPlayer 10.5 v6.0.12.1040 RealNetworks RealPlayer 10.5 RealNetworks RealPlayer 10.0 RealNetworks RealOne Player 2.0 RealNetworks RealOne Player 1.0 Microsoft AntiSpyware 1.0.509 (Beta 1) Kaspersky Labs Anti-Virus for Windows File Servers 5.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor lpCommandLine Application Path Vulnerability
Multiple vendor applications are prone to an arbitrary local code-execution vulnerability.
This is due to a design error in which malicious code may be executed in the context of the user running the affected application.
Multiple vendor applications are prone to an arbitrary local code-execution vulnerability.
This is due to a design error in which malicious code may be executed in the context of the user running the affected application.
Exploit / POC
Multiple Vendor lpCommandLine Application Path Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Multiple Vendor lpCommandLine Application Path Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Please see the references for more information and fixes.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Please see the references for more information and fixes.
References
Multiple Vendor lpCommandLine Application Path Vulnerability
References:
References: