2006-6979 | Amarok input validation (BID-22568 / XFDB-32512)
CVSS Meta Temp Score | Current Exploit Price (≈) | CTI Interest Score |
---|---|---|
6.6 | $0-$5k | 0.42 |
A vulnerability, which was classified as critical, has been found in Amarok (unknown version). This issue affects an unknown code. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-20. Impacted is confidentiality, integrity, and availability.
The bug was discovered 12/07/2006. The weakness was presented 02/08/2007 (Website). The advisory is shared at vupen.com. The identification of this vulnerability is CVE-2006-6979 since 02/08/2007. The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. Neither technical details nor an exploit are publicly available.
It is declared as proof-of-concept. The vulnerability was handled as a non-public zero-day exploit for at least 63 days. During that time the estimated underground price was around $0-$5k. The vulnerability scanner Nessus provides a plugin with the ID 24828 (GLSA-200703-11 : Amarok: User-assisted remote execution of arbitrary code), which helps to determine the existence of the flaw in a target environment. It is assigned to the family Gentoo Local Security Checks and running in the context local.
Upgrading eliminates this vulnerability. A possible mitigation has been published 2 months after the disclosure of the vulnerability.
The vulnerability is also documented in the databases at SecurityFocus (BID 22568), X-Force (32512), Secunia (SA23984), Vulnerability Center (SBV-14671) and Tenable (24828). See 34914 for similar entry.
Name
VulDB Meta Base Score: 7.3
VulDB Meta Temp Score: 6.6
VulDB Base Score: 7.3
VulDB Temp Score: 6.6
VulDB Vector: 🔍
VulDB Reliability: 🔍
AV | AC | Au | C | I | A |
---|---|---|---|---|---|
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
🔍 | 🔍 | 🔍 | 🔍 | 🔍 | 🔍 |
Vector | Complexity | Authentication | Confidentiality | Integrity | Availability |
---|---|---|---|---|---|
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
unlock | unlock | unlock | unlock | unlock | unlock |
VulDB Base Score: 🔍
VulDB Temp Score: 🔍
VulDB Reliability: 🔍
NVD Base Score: 🔍
Class: Privilege escalation
CWE: CWE-20
ATT&CK: Unknown
Local: No
Remote: Yes
Availability: 🔍
Status: Proof-of-Concept
Price Prediction: 🔍
Current Price Estimation: 🔍
0-Day | unlock | unlock | unlock | unlock |
---|---|---|---|---|
Today | unlock | unlock | unlock | unlock |
Nessus ID: 24828
Nessus Name: GLSA-200703-11 : Amarok: User-assisted remote execution of arbitrary code
Nessus File: 🔍
Nessus Risk: 🔍
Nessus Family: 🔍
Nessus Context: 🔍
OpenVAS ID: 58128
OpenVAS Name: Gentoo Security Advisory GLSA 200703-11 (amarok)
OpenVAS File: 🔍
OpenVAS Family: 🔍
Threat Intelligence
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍
Reaction Time: 🔍
0-Day Time: 🔍
Exposure Time: 🔍
Upgrade: vupen.com
12/07/2006 🔍
12/07/2006 🔍
01/16/2007 🔍
01/29/2007 🔍
02/08/2007 🔍
02/08/2007 🔍
02/08/2007 🔍
03/13/2007 🔍
03/16/2007 🔍
03/21/2007 🔍
04/02/2014 🔍
03/13/2015 🔍
07/13/2021 🔍Advisory: vupen.com
Status: Not defined
CVE: CVE-2006-6979 (🔍)
SecurityFocus: 22568 – Amarok Magnature Shell Command Injection Vulnerability
Secunia: 23984 – SUSE Update for Multiple Packages, Moderately Critical
X-Force: 32512
Vulnerability Center: 14671 – Amarok MagnaTune Command Execution Vulnerability, High
OSVDB: 33197 – CVE-2006-6979 – Amarok Magnature – Shell Command Injection Issue
Vupen: ADV-2007-0613
See also: 🔍
Created: 03/13/2015 12:16
Updated: 07/13/2021 11:10
Changes: (3) source_nessus_filename exploit_price_0day vulnerability_cvss2_nvd_basescore
Complete: 🔍
Download it now for free!