7.6
CVE-2009-3617
- EPSS 14.03%
- Veröffentlicht 20.10.2009 17:30:01
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tatsuhiro Tsujikawa ≫ Aria2 Version <= 1.6.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.3
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.4
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.5
Tatsuhiro Tsujikawa ≫ Aria2 Version0.12.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.12.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.2
Tatsuhiro Tsujikawa ≫ Aria2 Version0.14.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.2
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.3
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.0.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.1.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.1.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.2.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.3
Tatsuhiro Tsujikawa ≫ Aria2 Version1.4.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.4.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 14.03% | 0.937 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.