KTorrent Multiple Remote Vulnerabilities
BID:22930
Info
KTorrent Multiple Remote Vulnerabilities
| Bugtraq ID: | 22930 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1384 CVE-2007-1385 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 12 2007 12:00AM |
| Updated: | May 24 2007 07:21PM |
| Credit: | Bryan Burns of Juniper Networks is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9-SP3 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 SuSE Linux Desktop 1.0 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 Slackware Linux 11.0 Slackware Linux -current S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 Pardus Linux 2007.1 KTorrent KTorrent 2.1.1 KTorrent KTorrent 2.0.3 KTorrent KTorrent 1.2 Gentoo Linux |
| Not Vulnerable: |
KTorrent KTorrent 2.1.2 |
Discussion
KTorrent Multiple Remote Vulnerabilities
KTorrent is prone to multiple remote vulnerabilities, including a directory-traversal vulnerability and an unspecified vulnerability when processing messages with invalid chunk indexes.
Very little information is known about one of these issues. This BID will be updated as soon as more information becomes available.
An attacker can exploit the directory-traversal issue to overwrite arbitrary files on the user's system. Presumably, the unspecified vulnerability when processing messages with invalid chunk indexes will allow attackers to execute arbitrary code or to cause a denial of service, but this has not been confirmed.
Versions prior to 2.1.2 are vulnerable to these issues.
KTorrent is prone to multiple remote vulnerabilities, including a directory-traversal vulnerability and an unspecified vulnerability when processing messages with invalid chunk indexes.
Very little information is known about one of these issues. This BID will be updated as soon as more information becomes available.
An attacker can exploit the directory-traversal issue to overwrite arbitrary files on the user's system. Presumably, the unspecified vulnerability when processing messages with invalid chunk indexes will allow attackers to execute arbitrary code or to cause a denial of service, but this has not been confirmed.
Versions prior to 2.1.2 are vulnerable to these issues.
Exploit / POC
KTorrent Multiple Remote Vulnerabilities
An attacker can exploit this issue using a ktorrent client.
An attacker can exploit this issue using a ktorrent client.
Solution / Fix
KTorrent Multiple Remote Vulnerabilities
Solution:
The vendor released an update to address these issues. Please see the references for more information.
KTorrent KTorrent 2.0.3
Solution:
The vendor released an update to address these issues. Please see the references for more information.
KTorrent KTorrent 2.0.3
-
Ubuntu ktorrent_2.0.3+dfsg1-0ubuntu1.1_amd64.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/ktorrent/ktorrent_2.0.3+ dfsg1-0ubuntu1.1_amd64.deb -
Ubuntu ktorrent_2.0.3+dfsg1-0ubuntu1.1_i386.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/ktorrent/ktorrent_2.0.3+ dfsg1-0ubuntu1.1_i386.deb -
Ubuntu ktorrent_2.0.3+dfsg1-0ubuntu1.1_powerpc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/ktorrent/ktorrent_2.0.3+ dfsg1-0ubuntu1.1_powerpc.deb -
Ubuntu ktorrent_2.0.3+dfsg1-0ubuntu1.1_sparc.deb
Ubuntu 6.10:
http://security.ubuntu.com/ubuntu/pool/main/k/ktorrent/ktorrent_2.0.3+ dfsg1-0ubuntu1.1_sparc.deb
References
KTorrent Multiple Remote Vulnerabilities
References:
References:
- KTorrent 2.1.2 released (KTorrent)
- KTorrent Homepage (KTorrent)