exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Pardus Linux Security Advisory 2008.61

Pardus Linux Security Advisory 2008.61
Posted Nov 5, 2008
Authored by Pardus Linux, Pardus

Pardus Linux Security Advisory 2008-61 - Some vulnerabilities have been discovered in KTorrent, which can be exploited by malicious users to compromise a vulnerable system and malicious people to bypass certain security restrictions. Versions below 2.2.7-30-4 are affected.

tags | advisory, vulnerability
systems | linux
SHA-256 | 9561f7dade50a79ef90383d23eb5333696780886fc96417a1f90bdc16dc81273

Pardus Linux Security Advisory 2008.61

Change Mirror Download
------------------------------------------------------------------------
Pardus Linux Security Advisory 2008-61 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2008-11-05
Severity: 1
Type: Remote
------------------------------------------------------------------------

Summary
=======

Some vulnerabilities have been discovered in KTorrent, which can be
exploited by malicious users to compromise a vulnerable system and
malicious people to bypass certain security restrictions.


Description
===========

1) The web interface plugin does not properly restrict access to the
torrent upload functionality. This can be exploited to upload arbitrary
torrent files by sending specially crafted HTTP POST request to the
affected application.



2) The web interface plugin does not properly sanitise request
parameters before passing them to the PHP interpreter. This can be
exploited to inject and execute arbitrary PHP code by passing specially
crafted parameters to the PHP scripts of the web interface.



Successful exploitation of the vulnerabilities requires that the web
interface plugin is enabled (not the default setting).


Affected packages:

Pardus 2008:
ktorrent, all before 2.2.7-30-4


Resolution
==========

There are update(s) for ktorrent. You can update them via Package
Manager or with a single command from console:

pisi up ktorrent

References
==========

* http://bugs.pardus.org.tr/show_bug.cgi?id=8566
* http://secunia.com/advisories/32442/

------------------------------------------------------------------------

--
Pardus Security Team
http://security.pardus.org.tr


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close