CVE-2009-0753
mldonkey - information disclosure
EPSS 5.8%
Description
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files via a leading "//" (double slash) in the filename.
How to fix CVE-2009-0753
To remediate CVE-2009-0753, upgrade the affected package to a fixed version below.
- Debian/mldonkey—upgrade to 3.0.0-1 or later
- Debian/mldonkey—upgrade to 2.9.5-2+lenny1 or later
Is CVE-2009-0753 being exploited?
Moderate — EPSS is 5.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 3.0.0-1
- from 0, < 2.9.5-2+lenny1