Aria2 Project

Aria2

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 13.05.2026 14:55:09
  • Zuletzt bearbeitet 19.08.2026 12:43:34

aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

  • EPSS 0.35%
  • Veröffentlicht 02.01.2019 07:29:00
  • Zuletzt bearbeitet 21.11.2024 04:42:08

aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.