_______________________________________________________________________
Package : libtorrent-rasterbar
Date : June 24, 2009
Affected: 2009.1
_______________________________________________________________________
Problem Description:
A security vulnerability has been identified and corrected in
libtorrent-rasterbar:
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar
libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge
Torrent, and other applications, allows remote attackers to create
or overwrite arbitrary files via a .. (dot dot) and partial relative
pathname in a Multiple File Mode list element in a .torrent file
(CVE-2009-1760).
The updated packages have been patched to prevent this.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1760
_______________________________________________________________________