CVE-2009-3617
Published: 20 October 2009
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.
Notes
Author | Note |
---|---|
kees | should be mitigated by _FORTIFY_SOURCE in Intrepid and later. |
Priority
Status
Package | Release | Status |
---|---|---|
aria2 Launchpad, Ubuntu, Debian |
dapper |
Does not exist
|
hardy |
Ignored
(end of life)
|
|
intrepid |
Ignored
(end of life, was needed)
|
|
jaunty |
Ignored
(end of life)
|
|
karmic |
Ignored
(end of life)
|
|
lucid |
Not vulnerable
(1.6.2-3)
|
|
maverick |
Not vulnerable
(1.6.2-3)
|
|
natty |
Not vulnerable
(1.6.2-3)
|
|
oneiric |
Not vulnerable
(1.6.2-3)
|
|
upstream |
Released
(1.6.2)
|