2006-6979 | Amarok input validation (BID-22568 / XFDB-32512)


CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
6.6 $0-$5k 0.42

A vulnerability, which was classified as critical, has been found in Amarok (unknown version). This issue affects an unknown code. The manipulation with an unknown input leads to a privilege escalation vulnerability. Using CWE to declare the problem leads to CWE-20. Impacted is confidentiality, integrity, and availability.

The bug was discovered 12/07/2006. The weakness was presented 02/08/2007 (Website). The advisory is shared at vupen.com. The identification of this vulnerability is CVE-2006-6979 since 02/08/2007. The exploitation is known to be easy. The attack may be initiated remotely. No form of authentication is needed for a successful exploitation. Neither technical details nor an exploit are publicly available.

It is declared as proof-of-concept. The vulnerability was handled as a non-public zero-day exploit for at least 63 days. During that time the estimated underground price was around $0-$5k. The vulnerability scanner Nessus provides a plugin with the ID 24828 (GLSA-200703-11 : Amarok: User-assisted remote execution of arbitrary code), which helps to determine the existence of the flaw in a target environment. It is assigned to the family Gentoo Local Security Checks and running in the context local.

Upgrading eliminates this vulnerability. A possible mitigation has been published 2 months after the disclosure of the vulnerability.

The vulnerability is also documented in the databases at SecurityFocus (BID 22568), X-Force (32512), Secunia (SA23984), Vulnerability Center (SBV-14671) and Tenable (24828). See 34914 for similar entry.

Name

VulDB Meta Base Score: 7.3
VulDB Meta Temp Score: 6.6

VulDB Base Score: 7.3
VulDB Temp Score: 6.6
VulDB Vector: 🔍
VulDB Reliability: 🔍

AV AC Au C I A
🔍 🔍 🔍 🔍 🔍 🔍
🔍 🔍 🔍 🔍 🔍 🔍
🔍 🔍 🔍 🔍 🔍 🔍
Vector Complexity Authentication Confidentiality Integrity Availability
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock
unlock unlock unlock unlock unlock unlock


VulDB Base Score: 🔍
VulDB Temp Score: 🔍
VulDB Reliability: 🔍

NVD Base Score: 🔍

Class: Privilege escalation
CWE: CWE-20
ATT&CK: Unknown

Local: No
Remote: Yes

Availability: 🔍
Status: Proof-of-Concept

Price Prediction: 🔍
Current Price Estimation: 🔍


0-Day unlock unlock unlock unlock
Today unlock unlock unlock unlock


Nessus ID: 24828
Nessus Name: GLSA-200703-11 : Amarok: User-assisted remote execution of arbitrary code
Nessus File: 🔍
Nessus Risk: 🔍
Nessus Family: 🔍
Nessus Context: 🔍

OpenVAS ID: 58128
OpenVAS Name: Gentoo Security Advisory GLSA 200703-11 (amarok)
OpenVAS File: 🔍
OpenVAS Family: 🔍

Threat Intelligenceinfoedit

Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍Recommended: Upgrade
Status: 🔍

Reaction Time: 🔍
0-Day Time: 🔍
Exposure Time: 🔍

Upgrade: vupen.com

12/07/2006 🔍
12/07/2006 +0 days 🔍
01/16/2007 +40 days 🔍
01/29/2007 +13 days 🔍
02/08/2007 +10 days 🔍
02/08/2007 +0 days 🔍
02/08/2007 +0 days 🔍
03/13/2007 +33 days 🔍
03/16/2007 +3 days 🔍
03/21/2007 +5 days 🔍
04/02/2014 +2569 days 🔍
03/13/2015 +345 days 🔍
07/13/2021 +2314 days 🔍Advisory: vupen.com
Status: Not defined

CVE: CVE-2006-6979 (🔍)
SecurityFocus: 22568 – Amarok Magnature Shell Command Injection Vulnerability
Secunia: 23984 – SUSE Update for Multiple Packages, Moderately Critical
X-Force: 32512
Vulnerability Center: 14671 – Amarok MagnaTune Command Execution Vulnerability, High
OSVDB: 33197 – CVE-2006-6979 – Amarok Magnature – Shell Command Injection Issue
Vupen: ADV-2007-0613

See also: 🔍

Created: 03/13/2015 12:16
Updated: 07/13/2021 11:10
Changes: (3) source_nessus_filename exploit_price_0day vulnerability_cvss2_nvd_basescore
Complete: 🔍

Download it now for free!



Source link