|
Brought to you by:
Suppliers of:
|
|
|
| |
| There is an 'arbitrary file overwrite' vulnerability in libtorrent that allows an attacker to create and modify arbitrary files (and directories) with the effective rights of the user executing the vulnerable libtorrent-based application. |
| |
Credit:
The information has been provided by Dimitris Glynos.
The original article can be found at: http://census-labs.com/news/2009/06/08/libtorrent-rasterbar
|
| |
Vulnerable Systems:
* Rasterbar Software libtorrent version 0.14.3
Immune Systems:
* Rasterbar Software libtorrent version 0.14.4
libtorrent employs an insufficient path sanitization method that allows the formulation of relative paths from the path elements found in .torrent files. Specifically, this applies to .torrent files that describe multiple files. An adversary could use such relative paths, in a specially crafted .torrent file, to replace or create files in vulnerable systems.
CVE Information:
CVE-2009-1760
Disclosure Timeline:
May 27th, 2009 Vendor notification date
May 28th, 2009 Vendor acknowledgement date
June 1st, 2009 Vendor bugfix release date
June 8th, 2009 Public disclosure date:
|
|
|
|
|