[3.7] aria2: Metadata and potential password leak (CVE-2019-3500)
aria2c in aria2 1.33.1, when —log is used, can store an HTTP Basic
Authentication username and password in a file,
which might allow local users to obtain sensitive information by reading this file.
(from redmine: issue id 9900, created on 2019-01-23, closed on 2019-02-14)
- Revision c9121aba on 2019-01-31T13:18:36Z:
main/aria2: security fix (CVE-2019-3500) Fixes #9900