{ "schema_version": "1.4.0", "id": "GHSA-x93m-qj4v-vrm2", "modified": "2022-05-01T17:57:09Z", "published": "2022-05-01T17:57:09Z", "aliases": [ "CVE-2007-1799" ], "details": "Directory traversal vulnerability in torrent.cpp in KTorrent before 2.1.3 only checks for the \"..\" string, which allows remote attackers to overwrite arbitrary files via modified \"..\" sequences in a torrent filename, as demonstrated by \"../\" sequences, due to an incomplete fix for CVE-2007-1384.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2007-1799" }, { "type": "WEB", "url": "https://bugs.gentoo.org/show_bug.cgi?id=170303" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/33566" }, { "type": "WEB", "url": "http://bugs.kde.org/show_bug.cgi?id=143637" }, { "type": "WEB", "url": "http://secunia.com/advisories/24995" }, { "type": "WEB", "url": "http://secunia.com/advisories/25097" }, { "type": "WEB", "url": "http://secunia.com/advisories/26773" }, { "type": "WEB", "url": "http://security.gentoo.org/glsa/glsa-200705-01.xml" }, { "type": "WEB", "url": "http://www.debian.org/security/2007/dsa-1373" }, { "type": "WEB", "url": "http://www.mandriva.com/security/advisories?name=MDKSA-2007:095" }, { "type": "WEB", "url": "http://www.novell.com/linux/security/advisories/2007_007_suse.html" }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/23745" }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/usn-436-2" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2007-04-02T22:19:00Z" } }