[3.7] aria2: Metadata and potential password leak (CVE-2019-3500)
aria2c in aria2 1.33.1, when —log is used, can store an HTTP Basic
Authentication username and password in a file,
which might allow local users to obtain sensitive information by reading
this file.
References:
https://github.com/aria2/aria2/issues/1329
https://nvd.nist.gov/vuln/detail/CVE-2019-3500
Patch:
https://github.com/aria2/aria2/commit/37368130ca7de5491a75fd18a20c5c5cc641824a
(from redmine: issue id 9900, created on 2019-01-23, closed on 2019-02-14)
- Changesets:
- Revision c9121aba on 2019-01-31T13:18:36Z:
main/aria2: security fix (CVE-2019-3500)
Fixes #9900