Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Debian DSA-1373-1 Critical: Ktorrent Directory Traversal Risk

debian
Calendar Grey September 11, 2007
Debian Logo
To address the ktorrent vulnerability linked to directory traversal, prioritize input sanitization and file path validation to avert unauthorized overwrites
It was discovered that ktorrent, a BitTorrent client for KDE, was vulnerable to a directory traversal bug which potentially allowed remote users to overwrite arbitrary files.

Summary


For the old stable distribution (sarge), this package was not present.

For the unstable distribution (sid), this problem was fixed in version
2.2.1.dfsg.1-1.

We recommend that you upgrade your ktorrent package.


Upgrade instructions
- --------------------wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
will update the internal database
apt-get upgrade
will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 4.0 alias etch

Size/MD5 checksum: 663 ec1366a6819ce30b5891b7c4e0e51986
Size/MD5 checksum: 2183095 3aef60283e457b7e13c1719387251612
Size/MD5 checksum: 12570 09ef4b627881d0aa29f682dbcf860ae7

alpha architecture (DEC Alpha)

Size/MD5 checksum: 1678764 e9fec2e0c67431d8df32f9...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here