Oval Definition:oval:org.mitre.oval:def:12962
Revision Date:2014-06-23Version:20
Title:DSA-2047-1 aria2 -- insufficient input sanitising
Description:A vulnerability was discovered in aria2, a download client. The "name" attribute of the "file" element of metalink files is not properly sanitised before using it to download files. If a user is tricked into downloading from a specially crafted metalink file, this can be exploited to download files to directories outside of the intended download directory. For the stable distribution, this problem has been fixed in version 0.14.0-1+lenny2. For the unstable distribution, this problem has been fixed in version 1.9.3-1. We recommend that you upgrade your aria2 package.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-1512
DSA-2047-1
Platform(s):Debian GNU/Linux 5.0
Product(s):aria2
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is sparc
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is armel
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND aria2 DPKG is earlier than 0.14.0-1+lenny2
  • BACK