See how aria compares to other vendors in security performance
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.
Aria upstream has released 1.6.2 version fixing one security issue. From aria2-1.6.2 Release Notes: --------------------------
This release fixes segmentation fault error if URI to download contains printf format string and logging is enabled.
Fixed the bug that causes segmentation fault if req->getCurrentUrl() contains printf format string such as %d. The statement that causes this bug is useless and removed.
References: ---------- http://aria2.svn.sourceforge.net/viewvc/aria2/trunk/NEWS?revision=1586
Upstream patch: --------------- http://aria2.svn.sourceforge.net/viewvc/aria2/trunk/src/AbstractCommand.cc?r1=1539&r2=1572
CVE Request: ------------ http://www.openwall.com/lists/oss-security/2009/10/16/6