7.6
CVSSv2

CVE-2009-3617

Published: 20/10/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 676
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 prior to 1.6.2, when logging is enabled, allows remote malicious users to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.

Vulnerable Product Search on Vulmon Subscribe to Product

tatsuhiro tsujikawa aria2 1.4.0

tatsuhiro tsujikawa aria2 1.6.0

tatsuhiro tsujikawa aria2 0.13.0\\+1

tatsuhiro tsujikawa aria2 0.16.2

tatsuhiro tsujikawa aria2 0.15.2

tatsuhiro tsujikawa aria2 1.5.2

tatsuhiro tsujikawa aria2 0.16.0

tatsuhiro tsujikawa aria2 0.14.0

tatsuhiro tsujikawa aria2 0.15.1\\+1

tatsuhiro tsujikawa aria2 1.0.0

tatsuhiro tsujikawa aria2 0.13.2\\+1

tatsuhiro tsujikawa aria2 1.3.0

tatsuhiro tsujikawa aria2 0.12.0

tatsuhiro tsujikawa aria2 1.1.1

tatsuhiro tsujikawa aria2 0.13.1

tatsuhiro tsujikawa aria2 0.11.5

tatsuhiro tsujikawa aria2 1.5.1

tatsuhiro tsujikawa aria2 0.13.2

tatsuhiro tsujikawa aria2 0.15.3

tatsuhiro tsujikawa aria2 0.14.0\\+1

tatsuhiro tsujikawa aria2 0.13.1\\+1

tatsuhiro tsujikawa aria2 1.3.3

tatsuhiro tsujikawa aria2 1.3.1

tatsuhiro tsujikawa aria2 0.15.0

tatsuhiro tsujikawa aria2 1.4.1

tatsuhiro tsujikawa aria2

tatsuhiro tsujikawa aria2 0.11.4

tatsuhiro tsujikawa aria2 0.15.1\\+2

tatsuhiro tsujikawa aria2 1.5.0

tatsuhiro tsujikawa aria2 0.11.3

tatsuhiro tsujikawa aria2 1.3.2

tatsuhiro tsujikawa aria2 0.12.1

tatsuhiro tsujikawa aria2 0.13.0

tatsuhiro tsujikawa aria2 1.1.2

tatsuhiro tsujikawa aria2 1.2.0

tatsuhiro tsujikawa aria2 0.16.1

tatsuhiro tsujikawa aria2 0.15.1