73f53712-d028-11db-8c07-0211d85f11fbktorrent -- multiple vulnerabilities

Two problems have been found in KTorrent:

  • KTorrent does not properly sanitize file names to filter out ".." components, so it's possible for an attacker to create a malicious torrent in order to overwrite arbitrary files within the filesystem.
  • Messages with invalid chunk indexes aren't rejected.

Discovery 2007-03-09
Entry 2007-03-11
Modified 2007-03-14
lt 2.1.2

lt 20070311