CVE-2004-1302

The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yamt:yamt:0.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:50

Type Values Removed Values Added
References () http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html - () http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.html -
References () http://secunia.com/advisories/13554 - () http://secunia.com/advisories/13554 -
References () http://securitytracker.com/id?1012583 - () http://securitytracker.com/id?1012583 -
References () http://tigger.uic.edu/~jlongs2/holes/yamt.txt - Exploit, Vendor Advisory () http://tigger.uic.edu/~jlongs2/holes/yamt.txt - Exploit, Vendor Advisory
References () http://www.securityfocus.com/bid/11999 - () http://www.securityfocus.com/bid/11999 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/18614 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/18614 -

Information

Published : 2005-01-10 05:00

Updated : 2024-11-20 23:50


NVD link : CVE-2004-1302

Mitre link : CVE-2004-1302

CVE.ORG link : CVE-2004-1302


JSON object : View

Products Affected

yamt

  • yamt