GLSA Veteran

Joined: 12 May 2004 Posts: 1209
|
Posted: Sat Jan 15, 2011 10:26 pm Post subject: [ GLSA 201101-04 ] aria2: Directory traversal |
|
|
Gentoo Linux Security Advisory
Title: aria2: Directory traversal (GLSA 201101-04)
Severity: normal
Exploitable: remote
Date: January 15, 2011
Bug(s): #320975
ID: 201101-04
Synopsis
A directory traversal vulnerability has been found in aria2.
Background
aria2 is a download utility with resuming and segmented downloading
with HTTP/HTTPS/FTP/BitTorrent support.
Affected Packages
Package: net-misc/aria2
Vulnerable: < 1.9.3
Unaffected: >= 1.9.3
Architectures: All supported architectures
Description
A directory traversal vulnerability was discovered in aria2.
Impact
A remote attacker could entice a user to download from a specially
crafted metalink file, resulting in the creation of arbitrary files.
Workaround
There is no known workaround at this time.
Resolution
All aria2 users should upgrade to the latest version:
| Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/aria2-1.9.3" |
References
CVE-2010-1512 |
|