7.6
CVE-2009-3617
- EPSS 4.89%
- Veröffentlicht 20.10.2009 17:30:01
- Zuletzt bearbeitet 16.06.2026 23:12:01
- Quelle secalert@redhat.com
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tatsuhiro Tsujikawa ≫ Aria2 Version <= 1.6.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.3
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.4
Tatsuhiro Tsujikawa ≫ Aria2 Version0.11.5
Tatsuhiro Tsujikawa ≫ Aria2 Version0.12.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.12.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.13.2
Tatsuhiro Tsujikawa ≫ Aria2 Version0.14.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.2
Tatsuhiro Tsujikawa ≫ Aria2 Version0.15.3
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.0
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.1
Tatsuhiro Tsujikawa ≫ Aria2 Version0.16.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.0.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.1.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.1.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.2.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.3.3
Tatsuhiro Tsujikawa ≫ Aria2 Version1.4.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.4.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.0
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.1
Tatsuhiro Tsujikawa ≫ Aria2 Version1.5.2
Tatsuhiro Tsujikawa ≫ Aria2 Version1.6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.89% | 0.91 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-134 Use of Externally-Controlled Format String
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
http://aria2.svn.sourceforge.net/viewvc/aria2/trunk/NEWS?revision=1586
http://aria2.svn.sourceforge.net/viewvc/aria2/trunk/src/AbstractCommand.cc?r1=1539&r2=1572
http://marc.info/?l=oss-security&m=125568632528906&w=2
http://marc.info/?l=oss-security&m=125572053420493&w=2
http://osvdb.org/59087
http://secunia.com/advisories/31732
http://www.vupen.com/english/advisories/2009/2960
https://bugzilla.redhat.com/show_bug.cgi?id=529342
https://fedorahosted.org/rel-eng/ticket/2495