PT-2009-4230 · Libtorrent · Libtorrent

Census

·

Published

2009-06-11

·

Updated

2018-10-10

·

CVE-2009-1760

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions: libtorrent versions prior to 0.14.4
Description: A directory traversal issue exists, allowing remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.
Recommendations: For versions prior to 0.14.4, update to version 0.14.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of .torrent files from untrusted sources until the update is applied.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1760
DSA-1815-1

Affected Products

Libtorrent