Gentoo Linux Security Advisory GLSA 200907-14 - A directory traversal vulnerability in Rasterbar libtorrent might allow a remote attacker to overwrite arbitrary files. census reported a directory traversal vulnerability in src/torrent_info.cpp that can be triggered via .torrent files. Versions less than 0.13-r1 are affected.
2e799ebd355637e542c267e8331df9e50b6992123a5c166740bf71f8ea5e2b8e
Mandriva Linux Security Advisory 2009-139 - A security vulnerability has been identified and corrected in libtorrent-rasterbar. Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file. The updated packages have been patched to prevent this.
df968b48a75671252ad5e27d386882167cc1f161476de70fd745f1c69c1f311c
Debian Security Advisory 1815-1 - It was discovered that the Rasterbar Bittorrent library performed insufficient validation of path names specified in torrent files, which could lead to denial of service by overwriting files.
ad63608a9520d0d064fda0d70c6160937238a9bb33814e1fb611af3e163f35cd