aria2: Directory traversal
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201101-04 / aria2 |
| Release Date |
January 15, 2011 |
| Latest Revision |
January 15, 2011: 01 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/aria2 |
<
1.9.3 |
>=
1.9.3 |
All supported architectures
|
Related bugreports:
#320975
Synopsis
A directory traversal vulnerability has been found in aria2.
2.
Impact Information
Background
aria2 is a download utility with resuming and segmented downloading
with HTTP/HTTPS/FTP/BitTorrent support.
Description
A directory traversal vulnerability was discovered in aria2.
Impact
A remote attacker could entice a user to download from a specially
crafted metalink file, resulting in the creation of arbitrary files.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All aria2 users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/aria2-1.9.3"
|
4.
References
|