Oval Definition:oval:com.ubuntu.xenial:def:20185702000
Revision Date:2018-01-15Version:1
Title:CVE-2018-5702 on Ubuntu 16.04 LTS (xenial) - medium.
Description:Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2018-5702
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND The 'transmission' package in xenial was vulnerable but has been fixed (note: '2.84-3ubuntu3.1').
  • BACK