Your submission was sent successfully! Close

CVE-2009-3617

Published: 20 October 2009

Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details are obtained from third party information.

Notes

AuthorNote
kees
should be mitigated by _FORTIFY_SOURCE in Intrepid and later.
Priority

Medium

Status

Package Release Status
aria2
Launchpad, Ubuntu, Debian
dapper Does not exist

hardy Ignored
(reached end-of-life)
intrepid Needed
(reached end-of-life)
jaunty Ignored
(reached end-of-life)
karmic Ignored
(reached end-of-life)
lucid Not vulnerable
(1.6.2-3)
maverick Not vulnerable
(1.6.2-3)
natty Not vulnerable
(1.6.2-3)
oneiric Not vulnerable
(1.6.2-3)
precise Not vulnerable
(1.6.2-3)
upstream
Released (1.6.2)