CVE-2008-5905
EPSS 0.12%
Description
The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.
How to fix CVE-2008-5905
To remediate CVE-2008-5905, upgrade the affected package to a fixed version below.
- Debian/ktorrent—upgrade to 3.1.4+dfsg.1-1 or later
Is CVE-2008-5905 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 3.1.4+dfsg.1-1