Vulnerability Description
The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Yamt | Yamt | 0.5 |
References
- http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.h
- http://secunia.com/advisories/13554
- http://securitytracker.com/id?1012583
- http://tigger.uic.edu/~jlongs2/holes/yamt.txtExploitVendor Advisory
- http://www.securityfocus.com/bid/11999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18614
- http://rpmfind.net/linux/RPM/suse/updates/8.2/i386/rpm/i586/yamt-0.5-1277.i586.h
- http://secunia.com/advisories/13554
- http://securitytracker.com/id?1012583
- http://tigger.uic.edu/~jlongs2/holes/yamt.txtExploitVendor Advisory
- http://www.securityfocus.com/bid/11999
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18614
FAQ
What is CVE-2004-1302?
CVE-2004-1302 is a vulnerability with a CVSS score of 10.0 (HIGH). The id3tag_sort function in id3tag.c for YAMT 0.5 allows remote attackers to execute arbitrary commands via an MP3 file with double quotes in the Artist tag.
How severe is CVE-2004-1302?
CVE-2004-1302 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1302?
Check the references section above for vendor advisories and patch information. Affected products include: Yamt Yamt.