Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3 only checks for the .. string, which allows remote attackers to overwrite arbitrary files via modified .. sequences in a torrent filename, as demonstrated by ../ sequences, due to an incomplete fix for CVE-2007-1384.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ktorrent | Joris_guisson | 2.1.1 (including) | 2.1.1 (including) |
Ktorrent | Joris_guisson | 2.1.2 (including) | 2.1.2 (including) |
Ktorrent | Ubuntu | dapper | * |
Ktorrent | Ubuntu | edgy | * |
Ktorrent | Ubuntu | feisty | * |
Ktorrent | Ubuntu | upstream | * |