6.4
CVSSv2

CVE-2007-1799

Published: 02/04/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in torrent.cpp in KTorrent prior to 2.1.3 only checks for the ".." string, which allows remote malicious users to overwrite arbitrary files via modified ".." sequences in a torrent filename, as demonstrated by "../" sequences, due to an incomplete fix for CVE-2007-1384.

Vulnerable Product Search on Vulmon Subscribe to Product

joris guisson ktorrent 2.1.2

joris guisson ktorrent 2.1.1

Vendor Advisories

USN-436-1 fixed a vulnerability in KTorrent The original fix for path traversal was incomplete, allowing for alternate vectors of attack This update solves the problem ...
Debian Bug report logs - #432007 CVE-2007-1799: vulnerability in torrentcpp Package: ktorrent; Maintainer for ktorrent is Debian KDE Extras Team <pkg-kde-extras@listsaliothdebianorg>; Source for ktorrent is src:ktorrent (PTS, buildd, popcon) Reported by: Steffen Joeris <white@debianorg> Date: Fri, 6 Jul 2007 16 ...
It was discovered that ktorrent, a BitTorrent client for KDE, was vulnerable to a directory traversal bug which potentially allowed remote users to overwrite arbitrary files For the old stable distribution (sarge), this package was not present For the stable distribution (etch), this problem has been fixed in version 203+dfsg1-22etch1 For the ...