KTorrent Remote Directory Traversal Variant Vulnerability
BID:23745
Info
KTorrent Remote Directory Traversal Variant Vulnerability
| Bugtraq ID: | 23745 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1799 |
| Remote: | Yes |
| Local: | No |
| Published: | May 01 2007 12:00AM |
| Updated: | Oct 25 2007 02:56PM |
| Credit: | Bryan Burns of Juniper Networks is credited with the discovery of this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server SDK 9 SuSE SUSE Linux Enterprise Server 9 SP3 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SuSE Linux Openexchange Server SuSE Linux Enterprise Server 9-SP3 SuSE Linux Enterprise Server 9 SuSE Linux Enterprise Server 10 SuSE Linux Desktop 1.0 SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SuSE Linux Open-Xchange 4.1 S.u.S.E. SUSE CORE 9 for x86 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Office Server S.u.S.E. Linux Enterprise Server for S/390 9.0 S.u.S.E. Linux Enterprise Server for S/390 Pardus Linux 2007.1 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 KTorrent KTorrent 2.1.2 KTorrent KTorrent 2.1.1 KTorrent KTorrent 2.0.3 KTorrent KTorrent 1.2 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 |
| Not Vulnerable: |
KTorrent KTorrent 2.1.3 |
Discussion
KTorrent Remote Directory Traversal Variant Vulnerability
KTorrent is prone to a remote directory-traversal vulnerability.
An attacker can exploit this issue by using modified '..' sequences to overwrite arbitrary files on a victim user's system.
This issue is due to an incomplete vendor fix of the issue discussed in BID 22930.
Versions of KTorrent prior to 2.1.3 are vulnerable to this issue.
KTorrent is prone to a remote directory-traversal vulnerability.
An attacker can exploit this issue by using modified '..' sequences to overwrite arbitrary files on a victim user's system.
This issue is due to an incomplete vendor fix of the issue discussed in BID 22930.
Versions of KTorrent prior to 2.1.3 are vulnerable to this issue.
Exploit / POC
KTorrent Remote Directory Traversal Variant Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious torrent file with the affected application.
To exploit this issue, an attacker must entice an unsuspecting victim to open a malicious torrent file with the affected application.
Solution / Fix
KTorrent Remote Directory Traversal Variant Vulnerability
Solution:
The vendor released KTorrent 2.1.3 to address this issue. Please see the references for more information.
KTorrent KTorrent 1.2
KTorrent KTorrent 2.0.3
KTorrent KTorrent 2.1.1
KTorrent KTorrent 2.1.2
Solution:
The vendor released KTorrent 2.1.3 to address this issue. Please see the references for more information.
KTorrent KTorrent 1.2
-
KTorrent ktorrent-2.1.3.tar.gz
http://ktorrent.org/downloads/2.1.3/ktorrent-2.1.3.tar.gz
KTorrent KTorrent 2.0.3
-
Debian ktorrent_2.0.3+dfsg1-2etch1_alpha.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_alpha.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_amd64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_amd64.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_arm.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_arm.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_hppa.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_hppa.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_i386.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_i386.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_ia64.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_ia64.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_mips.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_mips.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_mipsel.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_mipsel.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_s390.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_s390.deb -
Debian ktorrent_2.0.3+dfsg1-2etch1_sparc.deb
Debian GNU/Linux 4.0 alias etch
http://security.debian.org/pool/updates/main/k/ktorrent/ktorrent_2.0.3 +dfsg1-2etch1_sparc.deb -
KTorrent ktorrent-2.1.3.tar.gz
http://ktorrent.org/downloads/2.1.3/ktorrent-2.1.3.tar.gz
KTorrent KTorrent 2.1.1
-
KTorrent ktorrent-2.1.3.tar.gz
http://ktorrent.org/downloads/2.1.3/ktorrent-2.1.3.tar.gz
KTorrent KTorrent 2.1.2
-
KTorrent ktorrent-2.1.3.tar.gz
http://ktorrent.org/downloads/2.1.3/ktorrent-2.1.3.tar.gz