LWN.net Logo

ktorrent: arbitrary uploads, code execution

Package(s):ktorrent CVE #(s):CVE-2008-5905 CVE-2008-5906
Created:January 27, 2009 Updated:February 24, 2009
Description: From the Ubuntu advisory:

It was discovered that KTorrent did not properly restrict access when using the web interface plugin. A remote attacker could use a crafted http request and upload arbitrary torrent files to trigger the start of downloads and seeding. (CVE-2008-5905)

It was discovered that KTorrent did not properly handle certain parameters when using the web interface plugin. A remote attacker could use crafted http requests to execute arbitrary PHP code. (CVE-2008-5906)

Alerts:
Gentoo 200902-05 2009-02-23
Ubuntu USN-711-1 2009-01-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds