Aller au contenu
Appaloosa Scout

Vulnérabilité · NVD

CVE-2018-1167

HIGH 8.8

EN This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player 1.0.69.336. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5501.

Vecteur d'attaque : Réseau Aucun privilège requis
Voir le vecteur CVSS brut
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS 4.82% au-dessus de la médiane percentile 91.1%

Apps suivies liées à cette CVE

Pour chaque app : la plage affectée, la version qui corrige, et où en est l'app suivie aujourd'hui.

  • Spotify macOS com.spotify.client
    Affecté Corrigé Dernière suivie 9.1.72 indéterminé
  • Spotify iOS ios:com.spotify.client
    Affecté Corrigé Dernière suivie 9.1.72 indéterminé
  • Spotify Android com.spotify.music
    Affecté Corrigé Dernière suivie 9.0.68.632 indéterminé
Configurations CPE vulnérables (3)
Vendor Produit Versions
spotify spotify
Toutes plateformes (wildcard)
spotify spotify
Toutes plateformes (wildcard)
spotify spotify
Toutes plateformes (wildcard)
Voir sur NVD ↗