Mandriva Linux Security Advisory 2010-106 – A vulnerability was discovered in aria2 which allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. This update fixes this issue. Packages for 2009.0 are provided as of the Extended Maintenance Program.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/89903/MDVSA-2010-106.txt
Source: https://packetstormsecurity.com/files/89903/Mandriva-Linux-Security-Advisory-2010-106.html