DEBIAN-CVE-2008-5905

Source
https://security-tracker.debian.org/tracker/CVE-2008-5905
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5905.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2008-5905
Upstream
Published
2009-01-15T17:30:00.343Z
Modified
2026-04-28T20:10:56.364624Z
Summary
[none]
Details

The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.

References

Affected packages

Debian:11 / ktorrent

Package

Name
ktorrent
Purl
pkg:deb/debian/ktorrent?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.4+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5905.json"

Debian:12 / ktorrent

Package

Name
ktorrent
Purl
pkg:deb/debian/ktorrent?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.4+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5905.json"

Debian:13 / ktorrent

Package

Name
ktorrent
Purl
pkg:deb/debian/ktorrent?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.4+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5905.json"

Debian:14 / ktorrent

Package

Name
ktorrent
Purl
pkg:deb/debian/ktorrent?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.4+dfsg.1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2008-5905.json"