CVE-2007-4100

NameCVE-2007-4100
DescriptionMLDonkey before 2.9.0 does not load certain code from $MLDONKEY/web_infos/ before the network modules become active, which allows remote attackers to bypass the IP blocklist.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs435439

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mldonkey (PTS)jessie3.1.5-2fixed
stretch3.1.5-3.1fixed
buster3.1.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mldonkeysource(unstable)2.9.0-1435439

Notes

[etch] - mldonkey <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems