Gentoo Archives: gentoo-announce

From: Pierre-Yves Rofes <py@g.o>
To: gentoo-announce@l.g.o
Cc: full-disclosure@××××××××××××××.uk, bugtraq@×××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200902-05 ] KTorrent: Multiple vulnerabilitites
Date: Mon, 23 Feb 2009 21:41:59
Message-Id: 49A31816.8090205@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200902-05
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: KTorrent: Multiple vulnerabilitites
9 Date: February 23, 2009
10 Bugs: #244741
11 ID: 200902-05
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Two vulnerabilities in the web interface plugin in KTorrent allow for
19 remote execution of code and arbitrary torrent uploads.
20
21 Background
22 ==========
23
24 KTorrent is a BitTorrent program for KDE.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-p2p/ktorrent < 2.2.8 >= 2.2.8
33
34 Description
35 ===========
36
37 The web interface plugin does not restrict access to the torrent upload
38 functionality (CVE-2008-5905) and does not sanitize request parameters
39 properly (CVE-2008-5906) .
40
41 Impact
42 ======
43
44 A remote attacker could send specially crafted parameters to the web
45 interface that would allow for arbitrary torrent uploads and remote
46 code execution with the privileges of the KTorrent process.
47
48 Workaround
49 ==========
50
51 Disabling the web interface plugin will prevent exploitation of both
52 issues. Click "Plugins" in the configuration menu and uncheck the
53 checkbox left of "WebInterface", then apply the changes.
54
55 Resolution
56 ==========
57
58 All KTorrent users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=net-p2p/ktorrent-2.2.8"
62
63 References
64 ==========
65
66 [ 1 ] CVE-2008-5905
67 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5905
68 [ 2 ] CVE-2008-5906
69 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5906
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200902-05.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 http://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2009 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature