Shareaza Update Notification Spoofing Vulnerability
BID:27171
Info
Shareaza Update Notification Spoofing Vulnerability
| Bugtraq ID: | 27171 |
| Class: | Design Error |
| CVE: |
CVE-2008-7164 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Shareaza Shareaza 2.2.1 0 Shareaza Shareaza 1.8.2 |
| Not Vulnerable: |
Shareaza Shareaza 2.3.1.0 |
Discussion
Shareaza Update Notification Spoofing Vulnerability
Shareaza is prone to a vulnerability that allows attackers to spoof update notifications.
An attacker can exploit this issue to spoof the content contained in the update notification. A successful exploit may allow an attacker to convince an unsuspecting victim to download and install malicious files. Other attacks are also possible.
This issue affects versions prior to Shareaza 2.3.1.0.
Shareaza is prone to a vulnerability that allows attackers to spoof update notifications.
An attacker can exploit this issue to spoof the content contained in the update notification. A successful exploit may allow an attacker to convince an unsuspecting victim to download and install malicious files. Other attacks are also possible.
This issue affects versions prior to Shareaza 2.3.1.0.
Exploit / POC
Solution / Fix
Shareaza Update Notification Spoofing Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Shareaza Update Notification Spoofing Vulnerability
References:
References:
- Shareaza 2.3.1.0 Release Notes (Shareaza)
- Shareaza Homepage (Shareaza)