Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.67399
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2047-1)
Summary:The remote host is missing an update for the Debian 'aria2' package(s) announced via the DSA-2047-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'aria2' package(s) announced via the DSA-2047-1 advisory.

Vulnerability Insight:
A vulnerability was discovered in aria2, a download client. The 'name' attribute of the 'file' element of metalink files is not properly sanitised before using it to download files. If a user is tricked into downloading from a specially crafted metalink file, this can be exploited to download files to directories outside of the intended download directory.

For the stable distribution (lenny), this problem has been fixed in version 0.14.0-1+lenny2.

For the unstable distribution (sid), this problem has been fixed in version 1.9.3-1.

We recommend that you upgrade your aria2 package.

Affected Software/OS:
'aria2' package(s) on Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-1512
BugTraq ID: 40142
http://www.securityfocus.com/bid/40142
Bugtraq: 20100513 Secunia Research: aria2 metalink "name" Directory Traversal Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/511280/100/0/threaded
Debian Security Information: DSA-2047 (Google Search)
http://www.debian.org/security/2010/dsa-2047
http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041753.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041754.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-May/041758.html
http://security.gentoo.org/glsa/glsa-201101-04.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2010:106
http://secunia.com/secunia_research/2010-71/
http://www.osvdb.org/64592
http://secunia.com/advisories/39529
http://secunia.com/advisories/39872
http://secunia.com/advisories/42906
SuSE Security Announcement: SUSE-SR:2010:014 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.html
SuSE Security Announcement: SUSE-SR:2010:017 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
http://www.vupen.com/english/advisories/2010/1228
http://www.vupen.com/english/advisories/2010/1229
http://www.vupen.com/english/advisories/2011/0116
CopyrightCopyright (C) 2010 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.