4.3
CVSSv2

CVE-2010-1512

Published: 17/05/2010 Updated: 10/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in aria2 prior to 1.9.3 allows remote malicious users to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tatsuhiro tsujikawa aria2 0.13.0\\+1

tatsuhiro tsujikawa aria2 1.5.1

tatsuhiro tsujikawa aria2 1.4.0

tatsuhiro tsujikawa aria2 1.1.2

tatsuhiro tsujikawa aria2 0.16.2

tatsuhiro tsujikawa aria2 0.14.0

tatsuhiro tsujikawa aria2 0.13.2

tatsuhiro tsujikawa aria2 1.2.0

tatsuhiro tsujikawa aria2 0.11.1\\+1

tatsuhiro tsujikawa aria2 0.11.1

tatsuhiro tsujikawa aria2 0.8.1

tatsuhiro tsujikawa aria2 0.8.0

tatsuhiro tsujikawa aria2 0.5.2

tatsuhiro tsujikawa aria2 0.5.1

tatsuhiro tsujikawa aria2 0.3.1\\+2

tatsuhiro tsujikawa aria2 0.3.1\\+1

tatsuhiro tsujikawa aria2 0.3.1

tatsuhiro tsujikawa aria2 1.9.0

tatsuhiro tsujikawa aria2 1.8.3

tatsuhiro tsujikawa aria2 1.6.3

tatsuhiro tsujikawa aria2 1.6.2

tatsuhiro tsujikawa aria2 0.15.1\\+1

tatsuhiro tsujikawa aria2 0.13.1\\+1

tatsuhiro tsujikawa aria2 1.5.2

tatsuhiro tsujikawa aria2 1.3.3

tatsuhiro tsujikawa aria2 1.3.1

tatsuhiro tsujikawa aria2 1.3.0

tatsuhiro tsujikawa aria2 0.16.1

tatsuhiro tsujikawa aria2 0.15.2

tatsuhiro tsujikawa aria2 0.12.1

tatsuhiro tsujikawa aria2 0.11.5

tatsuhiro tsujikawa aria2 0.12.0

tatsuhiro tsujikawa aria2 0.10.1

tatsuhiro tsujikawa aria2 0.10.0\\+1

tatsuhiro tsujikawa aria2 0.7.1

tatsuhiro tsujikawa aria2 0.7.0

tatsuhiro tsujikawa aria2 0.5.0

tatsuhiro tsujikawa aria2 0.4.1

tatsuhiro tsujikawa aria2 0.2.1\\+1

tatsuhiro tsujikawa aria2 0.2.1

tatsuhiro tsujikawa aria2 1.8.0

tatsuhiro tsujikawa aria2 1.7.2

tatsuhiro tsujikawa aria2 1.9.1

tatsuhiro tsujikawa aria2 1.5.0b\\+20090716

tatsuhiro tsujikawa aria2 0.15.1\\+2

tatsuhiro tsujikawa aria2 0.14.0\\+1

tatsuhiro tsujikawa aria2 1.5.0

tatsuhiro tsujikawa aria2 1.6.0

tatsuhiro tsujikawa aria2 0.15.3

tatsuhiro tsujikawa aria2 1.1.1

tatsuhiro tsujikawa aria2 0.15.0

tatsuhiro tsujikawa aria2 0.15.1

tatsuhiro tsujikawa aria2 0.11.3

tatsuhiro tsujikawa aria2 0.11.4

tatsuhiro tsujikawa aria2 0.11.0

tatsuhiro tsujikawa aria2 0.10.2\\+1

tatsuhiro tsujikawa aria2 0.10.2

tatsuhiro tsujikawa aria2 0.7.3

tatsuhiro tsujikawa aria2 0.7.2

tatsuhiro tsujikawa aria2 0.5.0\\+2

tatsuhiro tsujikawa aria2 0.5.0\\+1

tatsuhiro tsujikawa aria2 0.3.0

tatsuhiro tsujikawa aria2 0.2.1\\+2

tatsuhiro tsujikawa aria2 1.8.2

tatsuhiro tsujikawa aria2 1.8.1

tatsuhiro tsujikawa aria2 1.1.0

tatsuhiro tsujikawa aria2 1.0.1

tatsuhiro tsujikawa aria2 0.13.2\\+1

tatsuhiro tsujikawa aria2 1.6.1

tatsuhiro tsujikawa aria2 1.3.2

tatsuhiro tsujikawa aria2 1.4.1

tatsuhiro tsujikawa aria2 0.16.0

tatsuhiro tsujikawa aria2 1.0.0

tatsuhiro tsujikawa aria2 0.13.0

tatsuhiro tsujikawa aria2 0.13.1

tatsuhiro tsujikawa aria2 0.13.1\\+2

tatsuhiro tsujikawa aria2 0.11.2

tatsuhiro tsujikawa aria2 0.10.0

tatsuhiro tsujikawa aria2 0.9.0

tatsuhiro tsujikawa aria2 0.6.0\\+1

tatsuhiro tsujikawa aria2 0.6.0

tatsuhiro tsujikawa aria2 0.4.0

tatsuhiro tsujikawa aria2 0.3.2

tatsuhiro tsujikawa aria2 0.2.0

tatsuhiro tsujikawa aria2 0.1.0

tatsuhiro tsujikawa aria2 1.7.1

tatsuhiro tsujikawa aria2 1.7.0

tatsuhiro tsujikawa aria2

Vendor Advisories

A vulnerability was discovered in aria2, a download client The "name" attribute of the "file" element of metalink files is not properly sanitised before using it to download files If a user is tricked into downloading from a specially crafted metalink file, this can be exploited to download files to directories outside of the intended download di ...