Vulnerabilities > CVE-2005-0789 - Unspecified vulnerability in Limewire 3.9.6/4.6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN limewire
nessus
Summary
Directory traversal vulnerability in LimeWire 3.9.6 through 4.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in a magnet request.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200503-37.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200503-37 (LimeWire: Disclosure of sensitive information) Two input validation errors were found in the handling of Gnutella GET requests (CAN-2005-0788) and magnet requests (CAN-2005-0789). Impact : A remote attacker can craft a specific Gnutella GET request or use directory traversal on magnet requests to read arbitrary files on the system with the rights of the user running LimeWire. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 17667 |
published | 2005-04-01 |
reporter | This script is Copyright (C) 2005-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/17667 |
title | GLSA-200503-37 : LimeWire: Disclosure of sensitive information |
code |
|
References
- http://marc.info/?l=bugtraq&m=111082448213238&w=2
- http://marc.info/?l=bugtraq&m=111082448213238&w=2
- http://secunia.com/advisories/14555/
- http://secunia.com/advisories/14555/
- http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml
- http://www.gentoo.org/security/en/glsa/glsa-200503-37.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19695
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19695