Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 2 Jan 2019 11:04:23 +0400
From: Dhiraj Mishra <mishra.dhiraj95@...il.com>
To: oss-security@...ts.openwall.com
Subject: aria2 leaks passwords for HTTP based authentication

Hi List,


aria2 is a lightweight multi-protocol command-line utility which leaks data
or potential password via `--log=` attribute for HTTP based authentication
which might allow local attackers to obtain sensitive information. This
issue is somewhat similar to (2019/01/01/1).


It was observed that URL's which gets downloaded via `--log=` attribute
store’s sensitive information.

Example: aria2c --log=file https://user:passwd@...mple.com/


Later CVE-2019-3500 was assigned to this.




Thank you

@mishradhiraj_

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.