[Japanese]
|
JVNDB-2010-000029
|
Winny vulnerable to buffer overflow
|
Winny contains a buffer overflow vulnerability.
Winny is a P2P file sharing software. Winny contains a buffer overflow vulnerability.
This vulnerability is different from JVN#91740962 and JVN#74294680.
Makoto Iwamura of NTT Information Sharing Platform Laboratories reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Moti Joseph and Kobi Pariente reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
|
CVSS V2 Severity: Base Metrics 7.5 (High) [IPA Score]
- Access Vector: Network
- Access Complexity: Low
- Authentication: None
- Confidentiality Impact: Partial
- Integrity Impact: Partial
- Availability Impact: Partial
|
|
Isamu Kaneko
- Winny 2.0b7.1 and earlier
|
|
A remote attacker may be able to execute arbitary code.
|
[Do not use Winny]
Please discontinue use of Winny.
|
|
- Buffer Errors(CWE-119) [IPA Evaluation]
|
- CVE-2010-2360
|
- JVN : JVN#21471805
- National Vulnerability Database (NVD) : CVE-2010-2360
- ISS X-Force Database : 61276
|
- [2010/08/20]
Web page published
|