Source: transmission
Version: 2.94-2
Severity: important
Tags: security upstream
Control: found -1 2.92-2+deb9u1
Control: found -1 2.92-2

Hi,

The following vulnerability was published for transmission.

CVE-2018-10756[0]:
| Use-after-free in libtransmission/variant.c in Transmission before
| 3.00 allows remote attackers to cause a denial of service (crash) or
| possibly execute arbitrary code via a crafted torrent file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-10756
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-10756
[1] 
https://github.com/transmission/transmission/commit/2123adf8e5e1c2b48791f9d22fc8c747e974180e
[2] https://tomrichards.net/2020/05/cve-2018-10756-transmission/

Regards,
Salvatore

Reply via email to