Lucene search

K
cveMitreCVE-2009-1760
HistoryJun 11, 2009 - 9:30 p.m.

CVE-2009-1760

2009-06-1121:30:00
CWE-22
mitre
web.nvd.nist.gov
40
cve-2009-1760
directory traversal
rasterbar libtorrent
vulnerability
security
nvd
remote attackers
.torrent file

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.005

Percentile

77.2%

Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a … (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.

Affected configurations

Nvd
Node
rasterbar_softwarelibtorrentRange0.14.3
OR
rasterbar_softwarelibtorrentMatch0
OR
rasterbar_softwarelibtorrentMatch0.12
OR
rasterbar_softwarelibtorrentMatch0.12.1
VendorProductVersionCPE
rasterbar_softwarelibtorrent*cpe:2.3:a:rasterbar_software:libtorrent:*:*:*:*:*:*:*:*
rasterbar_softwarelibtorrent0cpe:2.3:a:rasterbar_software:libtorrent:0:*:*:*:*:*:*:*
rasterbar_softwarelibtorrent0.12cpe:2.3:a:rasterbar_software:libtorrent:0.12:*:*:*:*:*:*:*
rasterbar_softwarelibtorrent0.12.1cpe:2.3:a:rasterbar_software:libtorrent:0.12.1:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.3

Confidence

Low

EPSS

0.005

Percentile

77.2%