Oval Definition:oval:com.ubuntu.artful:def:20185702000
Revision Date:2018-01-15Version:1
Title:CVE-2018-5702 on Ubuntu 17.10 (artful) - medium.
Description:Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-5702
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND The 'transmission' package in artful was vulnerable but has been fixed (note: '2.92-2ubuntu3.1').
  • BACK