CVE-2009-1440
amule - insufficient input sanitising
EPSS 1.5%
Description
Incomplete blacklist vulnerability in DownloadListCtrl.cpp in amule 2.2.4 allows remote attackers to conduct argument injection attacks into a command for mplayer via a crafted filename.
How to fix CVE-2009-1440
To remediate CVE-2009-1440, upgrade the affected package to a fixed version below.
- Debian/amule—upgrade to 2.2.5-1.1 or later
- Debian/amule—upgrade to 2.2.1-1+lenny2 or later
Is CVE-2009-1440 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.2.5-1.1
- from 0, < 2.2.1-1+lenny2