| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.64252 |
| Kategorie: | Debian Local Security Checks |
| Titel: | Debian Security Advisory DSA 1817-1 (ctorrent) |
| Zusammenfassung: | Debian Security Advisory DSA 1817-1 (ctorrent) |
| Beschreibung: | The remote host is missing an update to ctorrent announced via advisory DSA 1817-1. Michael Brooks discovered that ctorrent, a text-mode bittorrent client, does not verify the length of file paths in torrent files. An attacker can exploit this via a crafted torrent that contains a long file path to execute arbitrary code with the rights of the user opening the file. The oldstable distribution (etch) does not contain ctorrent. For the stable distribution (lenny), this problem has been fixed in version 1.3.4-dnh3.2-1+lenny1. For the testing distribution (squeeze), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 1.3.4-dnh3.2-1.1. We recommend that you upgrade your ctorrent packages. Solution: http://www.securityspace.com/smysecure/catid.html?in=DSA%201817-1 |
| Querverweis: |
Common Vulnerability Exposure (CVE) ID: CVE-2009-1759 http://www.milw0rm.com/exploits/8470 http://www.openwall.com/lists/oss-security/2009/05/20/3 Debian Security Information: DSA-1817 (Google Search) http://www.debian.org/security/2009/dsa-1817 https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html BugTraq ID: 34584 http://www.securityfocus.com/bid/34584 http://secunia.com/advisories/34752 http://secunia.com/advisories/35499 http://secunia.com/advisories/36471 http://www.vupen.com/english/advisories/2009/1092 XForce ISS Database: ctorrent-btfiles-bo(49959) http://xforce.iss.net/xforce/xfdb/49959 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|