Login
Newsletter
Werbung

Sicherheit: Überschreiben von Dateien in libtorrent-rasterbar
Aktuelle Meldungen Distributionen
Name: Überschreiben von Dateien in libtorrent-rasterbar
ID: MDVSA-2009:139
Distribution: Mandriva
Plattformen: Mandriva 2009.1
Datum: Mi, 24. Juni 2009, 16:54
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760
Applikationen: Rasterbar libtorrent

Originalnachricht

This is a multi-part message in MIME format...

------------=_1245855271-22127-211


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2009:139
http://www.mandriva.com/security/
_______________________________________________________________________

Package : libtorrent-rasterbar
Date : June 24, 2009
Affected: 2009.1
_______________________________________________________________________

Problem Description:

A security vulnerability has been identified and corrected in
libtorrent-rasterbar:

Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar
libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge
Torrent, and other applications, allows remote attackers to create
or overwrite arbitrary files via a .. (dot dot) and partial relative
pathname in a Multiple File Mode list element in a .torrent file
(CVE-2009-1760).

The updated packages have been patched to prevent this.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2009.1:
018c83239c8d6d257e8f722abaf73ac4
2009.1/i586/libtorrent-rasterbar1-0.14.1-4.1mdv2009.1.i586.rpm
af514bb4fd8ff292d769ee200d1ca5f7
2009.1/i586/libtorrent-rasterbar-devel-0.14.1-4.1mdv2009.1.i586.rpm
26ef9d0a438bb34e12c301d25682c7c5
2009.1/i586/python-libtorrent-rasterbar-0.14.1-4.1mdv2009.1.i586.rpm
be0c5e47f7a9205785bea2cb8e879c77
2009.1/SRPMS/libtorrent-rasterbar-0.14.1-4.1mdv2009.1.src.rpm

Mandriva Linux 2009.1/X86_64:
0d5fd577ea535f7f440f11b172d2a5f3
2009.1/x86_64/lib64torrent-rasterbar1-0.14.1-4.1mdv2009.1.x86_64.rpm
ddd105e9179360e4c6c5fb77cc2635db
2009.1/x86_64/lib64torrent-rasterbar-devel-0.14.1-4.1mdv2009.1.x86_64.rpm
bd3517f878999688492af5e93080df93
2009.1/x86_64/python-libtorrent-rasterbar-0.14.1-4.1mdv2009.1.x86_64.rpm
be0c5e47f7a9205785bea2cb8e879c77
2009.1/SRPMS/libtorrent-rasterbar-0.14.1-4.1mdv2009.1.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFKQhO0mqjQ0CJFipgRAtU8AKDBOKICcqU/z1ZssSIAlry8zaLLjACg3I6x
mLZjhVni+E+8POjvi/7Ta6Q=
=7iKP
-----END PGP SIGNATURE-----


------------=_1245855271-22127-211
Content-Type: text/plain; name="message-footer.txt"
Content-Disposition: inline; filename="message-footer.txt"
Content-Transfer-Encoding: 8bit

To unsubscribe, send a email to sympa@mandrivalinux.org
with this subject : unsubscribe security-announce
_______________________________________________________
Want to buy your Pack or Services from Mandriva?
Go to http://www.mandrivastore.com
Join the Club : http://www.mandrivaclub.com
_______________________________________________________

------------=_1245855271-22127-211--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung