It has been discovered that mldonkey, a client for several P2P networks, allows attackers to download arbitrary files using crafted requests to the HTTP console.
The old stable distribution (etch) is not affected by this problem.
For the stable distribution (lenny), this problem has been fixed in version 2.9.5-2+lenny1.
For the unstable distribution (sid), this problem will be fixed soon.
We recommend that you upgrade your mldonkey packages.
MD5 checksums of the listed files are available in the original advisory.