Full Disclosure mailing list archives
[ GLSA 201101-04 ] aria2: Directory traversal
From: Tobias Heinlein <keytoaster () gentoo org>
Date: Sat, 15 Jan 2011 22:46:55 +0100
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201101-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: aria2: Directory traversal Date: January 15, 2011 Bugs: #320975 ID: 201101-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A directory traversal vulnerability has been found in aria2. Background ========== aria2 is a download utility with resuming and segmented downloading with HTTP/HTTPS/FTP/BitTorrent support. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/aria2 < 1.9.3 >= 1.9.3 Description =========== A directory traversal vulnerability was discovered in aria2. Impact ====== A remote attacker could entice a user to download from a specially crafted metalink file, resulting in the creation of arbitrary files. Workaround ========== There is no known workaround at this time. Resolution ========== All aria2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-misc/aria2-1.9.3" References ========== [ 1 ] CVE-2010-1512 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1512 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201101-04.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security () gentoo org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2011 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5
Attachment:
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- [ GLSA 201101-04 ] aria2: Directory traversal Tobias Heinlein (Jan 15)