[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-1967-1 transmission -- directory traversal

ID: oval:org.secpod.oval:def:600098Date: (C)2011-01-28   (M)2024-01-29
Class: PATCHFamily: unix




Dan Rosenberg discovered that Transmission, a lightwight client for the Bittorrent filesharing protocol performs insufficient sanitising of file names specified in .torrent files. This could lead to the overwrite of local files with the privileges of the user running Transmission if the user is tricked into opening a malicious torrent file. For the stable distribution , this problem has been fixed in version 1.22-1+lenny2. For the unstable distribution , this problem has been fixed in version 1.77-1. We recommend that you upgrade your transmission packages.

Platform:
Debian 5.0
Product:
transmission
Reference:
DSA-1967-1
CVE-2010-0012
CVE    1
CVE-2010-0012
CPE    1
cpe:/o:debian:debian_linux:5.0

© SecPod Technologies