Unrated severityOSV Advisory· Published Jan 2, 2019· Updated Aug 4, 2024
CVE-2019-3500
CVE-2019-3500
Description
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
Affected products
9- osv-coords8 versionspkg:rpm/opensuse/aria2&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/aria2&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/aria2&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/aria2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/aria2&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/aria2&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/aria2&distro=SUSE%20Package%20Hub%2015%20SP2pkg:rpm/suse/aria2&distro=SUSE%20Package%20Hub%2015%20SP3
< 1.33.1-bp150.3.7.1+ 7 more
- (no CPE)range: < 1.33.1-bp150.3.7.1
- (no CPE)range: < 1.35.0-bp153.2.3.1
- (no CPE)range: < 1.35.0-bp153.2.3.1
- (no CPE)range: < 1.36.0-1.2
- (no CPE)range: < 1.33.1-bp150.3.7.1
- (no CPE)range: < 1.35.0-bp153.2.3.1
- (no CPE)range: < 1.35.0-bp153.2.3.1
- (no CPE)range: < 1.35.0-bp153.2.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/532M22TAOOIY3J4XX4R7BLZHXJRUSBQ2/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MUUYDELHRLVE2AFNVR3OJ6ILUKVLY4B/mitrevendor-advisoryx_refsource_FEDORA
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U5OLPTVYHJZJ2MVEXJCNPXBSFPVPE4XX/mitrevendor-advisoryx_refsource_FEDORA
- usn.ubuntu.com/3965-1/mitrevendor-advisoryx_refsource_UBUNTU
- github.com/aria2/aria2/issues/1329mitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2019/01/msg00012.htmlmitremailing-listx_refsource_MLIST
- lists.debian.org/debian-lts-announce/2021/12/msg00039.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.