Go to:
Gentoo Home
Documentation
Forums
Lists
Bugs
Planet
Store
Wiki
Get Gentoo!
Gentoo's Bugzilla – Attachment 170106 Details for
Bug 244741
net-p2p/ktorrent <2.2.8 web interface plugin vulnerable to PHP injection (CVE-2008-{5905,5906})
Home
|
New
–
[Ex]
|
Browse
|
Search
|
Privacy Policy
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
ktorrent-3.1.3-upload.patch
ktorrent-3.1.3-upload.patch (text/plain), 734 bytes, created by
Robert Buchholz (RETIRED)
on 2008-10-28 14:59:32 UTC
(
hide
)
Description:
ktorrent-3.1.3-upload.patch
Filename:
MIME Type:
Creator:
Robert Buchholz (RETIRED)
Created:
2008-10-28 14:59:32 UTC
Size:
734 bytes
patch
obsolete
>--- ktorrent-3.1.3/plugins/webinterface/httpserver.cpp 2008-10-06 18:43:01.000000000 +0200 >+++ ktorrent-3.1.4/plugins/webinterface/httpserver.cpp 2008-10-19 12:23:34.000000000 +0200 >@@ -450,9 +450,17 @@ > void HttpServer::handleTorrentPost(HttpClientHandler* hdlr,const QHttpRequestHeader & hdr,const QByteArray & data) > { > const char* ptr = data.data(); >- Uint32 len = data.size(); >+ int len = data.size(); > int pos = QString(data).indexOf("\r\n\r\n"); > >+ if (!session.logged_in || !checkSession(hdr)) >+ { >+ // You can't post torrents if you are not logged in >+ // or the session is not OK >+ redirectToLoginPage(hdlr); >+ return; >+ } >+ > if (pos == -1 || pos + 4 >= len) > { > HttpResponseHeader rhdr(500);
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 244741
: 170106 |
170108
|
170109
|
170111