Jump to content
Compatible Support Forums
Sign in to follow this  
news

[Security Announce] [ MDVSA-2009:139 ] libtorrent-rasterbar

Recommended Posts

This is a multi-part message in MIME format...

 

------------=_1245855271-22127-211

 

 

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA1

 

_______________________________________________________________________

 

Mandriva Linux Security Advisory MDVSA-2009:139

http://www.mandriva.com/security/

_______________________________________________________________________

 

Package : libtorrent-rasterbar

Date : June 24, 2009

Affected: 2009.1

_______________________________________________________________________

 

Problem Description:

 

A security vulnerability has been identified and corrected in

libtorrent-rasterbar:

 

Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar

libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge

Torrent, and other applications, allows remote attackers to create

or overwrite arbitrary files via a .. (dot dot) and partial relative

pathname in a Multiple File Mode list element in a .torrent file

(CVE-2009-1760).

 

The updated packages have been patched to prevent this.

_______________________________________________________________________

 

References:

 

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1760

_______________________________________________________________________

 

Updated Packages:

 

Mandriva Linux 2009.1:

018c83239c8d6d257e8f722abaf73ac4 2009.1/i586/libtorrent-rasterbar1-0.14.1-4.1mdv2009.1.i586.rpm

af514bb4fd8ff292d769ee200d1ca5f7 2009.1/i586/libtorrent-rasterbar-devel-0.14.1-4.1mdv2009.1.i586.rpm

26ef9d0a438bb34e12c301d25682c7c5 2009.1/i586/python-libtorrent-rasterbar-0.14.1-4.1mdv2009.1.i586.rpm

be0c5e47f7a9205785bea2cb8e879c77 2009.1/SRPMS/libtorrent-rasterbar-0.14.1-4.1mdv2009.1.src.rpm

 

Mandriva Linux 2009.1/X86_64:

0d5fd577ea535f7f440f11b172d2a5f3 2009.1/x86_64/lib64torrent-rasterbar1-0.14.1-4.1mdv2009.1.x86_64.rpm

ddd105e9179360e4c6c5fb77cc2635db 2009.1/x86_64/lib64torrent-rasterbar-devel-0.14.1-4.1mdv2009.1.x86_64.rpm

bd3517f878999688492af5e93080df93 2009.1/x86_64/python-libtorrent-rasterbar-0.14.1-4.1mdv2009.1.x86_64.rpm

be0c5e47f7a9205785bea2cb8e879c77 2009.1/SRPMS/libtorrent-rasterbar-0.14.1-4.1mdv2009.1.src.rpm

_______________________________________________________________________

 

To upgrade automatically use MandrivaUpdate or urpmi. The verification

of md5 checksums and GPG signatures is performed automatically for you.

 

All packages are signed by Mandriva for security. You can obtain the

GPG public key of the Mandriva Security Team by executing:

 

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 

You can view other update advisories for Mandriva Linux at:

 

http://www.mandriva.com/security/advisories

 

If you want to report vulnerabilities, please contact

 

security_(at)_mandriva.com

_______________________________________________________________________

 

Type Bits/KeyID Date User ID

pub 1024D/22458A98 2000-07-10 Mandriva Security Team

 

-----BEGIN PGP SIGNATURE-----

Version: GnuPG v1.4.9 (GNU/Linux)

 

iD8DBQFKQhO0mqjQ0CJFipgRAtU8AKDBOKICcqU/z1ZssSIAlry8zaLLjACg3I6x

mLZjhVni+E+8POjvi/7Ta6Q=

=7iKP

-----END PGP SIGNATURE-----

 

 

------------=_1245855271-22127-211

Content-Type: text/plain; name="message-footer.txt"

Content-Disposition: inline; filename="message-footer.txt"

Content-Transfer-Encoding: 8bit

 

To unsubscribe, send a email to sympa ( -at -) mandrivalinux.org

with this subject : unsubscribe security-announce

_______________________________________________________

Want to buy your Pack or Services from Mandriva?

Go to http://www.mandrivastore.com

Join the Club : http://www.mandrivaclub.com

_______________________________________________________

 

------------=_1245855271-22127-211--

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×