CVE-2019-3500

Name
CVE-2019-3500
Description
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://github.com/aria2/aria2/issues/1329
Mailing List https://lists.debian.org/debian-lts-announce/2019/01/msg00012.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MUUYDELHRLVE2AFNVR3OJ6ILUKVLY4B/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/532M22TAOOIY3J4XX4R7BLZHXJRUSBQ2/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U5OLPTVYHJZJ2MVEXJCNPXBSFPVPE4XX/
UBUNTU https://usn.ubuntu.com/3965-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:aria2_project:aria2:1.33.1:*:*:*:*:*:*:* aria2 == None == 1.33.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status