cbcvebase.
CVE-2009-1760
published 2009-06-11

CVE-2009-1760: Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other…

PriorityP429medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
2.01%
78.7th percentile
Directory traversal vulnerability in src/torrent_info.cpp in Rasterbar libtorrent before 0.14.4, as used in firetorrent, qBittorrent, deluge Torrent, and other applications, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) and partial relative pathname in a Multiple File Mode list element in a .torrent file.

Affected

5 ranges
VendorProductVersion rangeFixed in
debianlibtorrent-rasterbar< libtorrent-rasterbar 0.14.4-1 (bookworm)libtorrent-rasterbar 0.14.4-1 (bookworm)
rasterbar_softwarelibtorrent<= 0.14.3
rasterbar_softwarelibtorrent
rasterbar_softwarelibtorrent
rasterbar_softwarelibtorrent

CVSS provenance

nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.