[isalist] FW: [ GLSA 200705-01 ] Ktorrent: Multiple vulnerabilities
- From: "Jim Harrison" <Jim@xxxxxxxxxxxx>
- To: <isalist@xxxxxxxxxxxxx>
- Date: Wed, 2 May 2007 06:37:55 -0700
http://www.ISAserver.org
-------------------------------------------------------
Whodathunkit; a torrent client with vulnerabilities...
Wait; it's not a Windows version - this has to be a fake!
:-P
-----Original Message-----
From: Raphael Marichez [mailto:falco@xxxxxxxxxx]
Sent: Tuesday, May 01, 2007 11:32 AM
To: gentoo-announce@xxxxxxxxxx
Cc: bugtraq@xxxxxxxxxxxxxxxxx; full-disclosure@xxxxxxxxxxxxxxxxx;
security-alerts@xxxxxxxxxxxxxxxxx
Subject: [ GLSA 200705-01 ] Ktorrent: Multiple vulnerabilities
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200705-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: Ktorrent: Multiple vulnerabilities
Date: May 01, 2007
Bugs: #170303
ID: 200705-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in Ktorrent allowing for
the remote execution of arbitrary code and a Denial of Service.
Background
==========
Ktorrent is a Bittorrent client for KDE.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-p2p/ktorrent < 2.1.3 >= 2.1.3
Description
===========
Bryan Burns of Juniper Networks discovered a vulnerability in
chunkcounter.cpp when processing large or negative idx values, and a
directory traversal vulnerability in torrent.cpp.
Impact
======
A remote attacker could entice a user to download a specially crafted
torrent file, possibly resulting in the remote execution of arbitrary
code with the privileges of the user running Ktorrent.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Ktorrent users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-p2p/ktorrent-2.1.3"
References
==========
[ 1 ] CVE-2007-1384
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1384
[ 2 ] CVE-2007-1385
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1385
[ 3 ] CVE-2007-1799
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1799
Availability
============
This GLSA and any updates to it are available for viewing at the Gentoo
Security Website:
http://security.gentoo.org/glsa/glsa-200705-01.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@xxxxxxxxxx or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its
owner(s).
The contents of this document are licensed under the Creative Commons -
Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/2.5
All mail to and from this domain is GFI-scanned.
------------------------------------------------------
List Archives: http://www.freelists.org/archives/isalist/
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/
ISA Server Blogs: http://blogs.isaserver.org/
------------------------------------------------------
Visit TechGenix.com for more information about our other sites:
http://www.techgenix.com
------------------------------------------------------
To unsubscribe visit http://www.isaserver.org/pages/isalist.asp
Report abuse to listadmin@xxxxxxxxxxxxx
Other related posts:
- » [isalist] FW: [ GLSA 200705-01 ] Ktorrent: Multiple vulnerabilities