CVE-2010-0012: Path Traversal
Published Jan 8, 2010
·Updated
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
Affected Software
8 affected components
transmissionbt Transmission=1.22
transmissionbt Transmission=1.34
transmissionbt Transmission=1.75
transmissionbt Transmission=1.76
Debian Debian Linux=5.0
openSUSE openSUSE=11.0
openSUSE openSUSE=11.1
openSUSE openSUSE=11.2
Remediation
Patch Available
Patch Available
Event History
Jan 8, 2010
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-0012?
CVE-2010-0012 has a moderate severity rating due to its potential for remote code execution through directory traversal.
2
How do I fix CVE-2010-0012?
To fix CVE-2010-0012, upgrade Transmission to the latest version that addresses this vulnerability.
3
Which versions of Transmission are affected by CVE-2010-0012?
CVE-2010-0012 affects Transmission versions 1.22, 1.34, 1.75, and 1.76.
4
Can CVE-2010-0012 be exploited remotely?
Yes, CVE-2010-0012 can be exploited remotely by an attacker using a crafted .torrent file.
5
Is it safe to use older versions of Transmission with CVE-2010-0012?
It is not safe to use older versions of Transmission vulnerable to CVE-2010-0012, as it allows file overwriting.