Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200902-05
https://security.gentoo.org/
Severity: High
Title: KTorrent: Multiple vulnerabilitites
Date: February 23, 2009
Bugs: #244741
ID: 200902-05
Synopsis
=======
Two vulnerabilities in the web interface plugin in KTorrent allow for
remote execution of code and arbitrary torrent uploads.
Background
=========
KTorrent is a BitTorrent program for KDE.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-p2p/ktorrent < 2.2.8 >= 2.2.8
==========
The web interface plugin does not restrict access to the torrent upload
functionality (CVE-2008-5905) and does not sanitize request parametersproperly (CVE-2008-5906) .
Impact
=...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.