| Vulnerability Name: | CVE-2010-0012 (CCN-55454) | ||||||||||||||||||||||||
| Assigned: | 2009-12-26 | ||||||||||||||||||||||||
| Published: | 2009-12-26 | ||||||||||||||||||||||||
| Updated: | 2017-08-17 | ||||||||||||||||||||||||
| Summary: | Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file. | ||||||||||||||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||
| CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
| Vulnerability Type: | CWE-22 | ||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2010-0012 Source: SUSE Type: UNKNOWN SUSE-SA:2010:008 Source: SECUNIA Type: UNKNOWN 37993 Source: CCN Type: SA38005 Transmission "name" Key Directory Traversal Vulnerability Source: SECUNIA Type: UNKNOWN 38005 Source: CONFIRM Type: UNKNOWN http://security.debian.org/pool/updates/main/t/transmission/transmission_1.22-1+lenny2.diff.gz Source: CONFIRM Type: UNKNOWN http://trac.transmissionbt.com/changeset/9829/ Source: CONFIRM Type: UNKNOWN http://trac.transmissionbt.com/wiki/Changes#version-1.77 Source: DEBIAN Type: UNKNOWN DSA-1967 Source: DEBIAN Type: DSA-1967 transmission -- directory traversal Source: MLIST Type: UNKNOWN [debian-devel-changes] 20100105 Accepted transmission 1.77-1 (source all amd64) Source: MLIST Type: UNKNOWN [oss-security] 20100106 CVE Request: Transmission Source: MLIST Type: UNKNOWN [oss-security] 20100106 Re: CVE Request: Transmission Source: CCN Type: OSVDB ID: 61601 Transmission libtransmission/metainfo.c Torrent File Traversal Arbitrary File Overwrite Source: CCN Type: BID-37659 Transmission Arbitrary File Overwrite Vulnerability Source: CCN Type: Transmission Web site Transmission Source: CCN Type: USN-885-1 Transmission vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2010-0071 Source: CCN Type: Ubuntu Bug #500625 Local file overwriting due to directory traversal Source: XF Type: UNKNOWN transmission-name-directory-traversal(55454) Source: XF Type: UNKNOWN transmission-name-directory-traversal(55454) Source: CONFIRM Type: UNKNOWN https://launchpad.net/bugs/500625 Source: SUSE Type: SUSE-SA:2010:008 Acrobat Reader security problems | ||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||