CVE-2009-1760

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/06/2009
Last modified:
09/04/2025

Description

Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rasterbar_software:libtorrent:*:*:*:*:*:*:*:* 0.14.3 (including)
cpe:2.3:a:rasterbar_software:libtorrent:0:*:*:*:*:*:*:*
cpe:2.3:a:rasterbar_software:libtorrent:0.12:*:*:*:*:*:*:*
cpe:2.3:a:rasterbar_software:libtorrent:0.12.1:*:*:*:*:*:*:*