KaZaA Advertisement Local Zone Vulnerability
BID:6543
Info
KaZaA Advertisement Local Zone Vulnerability
| Bugtraq ID: | 6543 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability is credited to "David Krum" <[email protected]>. |
| Vulnerable: |
KaZaA KaZaA Media Desktop 2.0 |
| Not Vulnerable: | |
Discussion
KaZaA Advertisement Local Zone Vulnerability
A vulnerability has been discovered in KaZaA related to the displaying of advertisments. It has been reported that KaZaA advertisements are rendered in the MSIE local zone. This presents a security risk as it is possible for malicious advertisement content to execute arbitrary commands on client systems. This issue may also be exploited to disclose the contents of system files.
This may allow unknown and untrusted remote content to compromise a users system.
A vulnerability has been discovered in KaZaA related to the displaying of advertisments. It has been reported that KaZaA advertisements are rendered in the MSIE local zone. This presents a security risk as it is possible for malicious advertisement content to execute arbitrary commands on client systems. This issue may also be exploited to disclose the contents of system files.
This may allow unknown and untrusted remote content to compromise a users system.
Exploit / POC
KaZaA Advertisement Local Zone Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
KaZaA Advertisement Local Zone Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.