linuxdcpp-team team mailing list archive
-
linuxdcpp-team team
-
Mailing list archive
-
Message #08456
[Bug 1502650] [NEW] DC++ 0.851 - Arbitrary code execution
*** This bug is a security vulnerability ***
Private security bug reported:
Details and PoC:
http://kacperrybczynski.com/research/dcpp_851_arbitrary_code_execution/
By supplying an UNC path in the *.dcext plugin file or main/pm hub chat,
a remote file will be automatically downloaded, which can result in
arbitrary code execution.
** Affects: dcplusplus
Importance: Undecided
Status: New
--
You received this bug notification because you are a member of
Dcplusplus-team, which is subscribed to DC++.
https://bugs.launchpad.net/bugs/1502650
Title:
DC++ 0.851 - Arbitrary code execution
Status in DC++:
New
Bug description:
Details and PoC:
http://kacperrybczynski.com/research/dcpp_851_arbitrary_code_execution/
By supplying an UNC path in the *.dcext plugin file or main/pm hub
chat, a remote file will be automatically downloaded, which can result
in arbitrary code execution.
To manage notifications about this bug go to:
https://bugs.launchpad.net/dcplusplus/+bug/1502650/+subscriptions
Follow ups
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: eMTee, 2016-09-14
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2016-09-14
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-07
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2015-10-07
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-07
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2015-10-06
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-06
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-06
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-06
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-06
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-05
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-05
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2015-10-05
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-05
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-05
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Fredrik Ullner, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: eMTee, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: Kacper, 2015-10-04
-
[Bug 1502650] Re: DC++ 0.851 - Arbitrary code execution
From: poy, 2015-10-04