MLDonkey before 2.9.0 does not load certain code from $MLDONKEY/web_infos/ before the network modules become active, which allows remote attackers to bypass the IP blocklist.
Link | Tags |
---|---|
http://secunia.com/advisories/26230 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/25093 | exploit vdb entry patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/35656 | vdb entry |
http://sourceforge.net/project/shownotes.php?release_id=527976 | |
http://osvdb.org/38626 | vdb entry |