Oval Definition:oval:org.mitre.oval:def:13619
Revision Date:2014-06-23Version:20
Title:DSA-1967-1 transmission -- directory traversal
Description:Dan Rosenberg discovered that Transmission, a lightwight client for the Bittorrent filesharing protocol performs insufficient sanitising of file names specified in .torrent files. This could lead to the overwrite of local files with the privileges of the user running Transmission if the user is tricked into opening a malicious torrent file. For the stable distribution, this problem has been fixed in version 1.22-1+lenny2. For the unstable distribution, this problem has been fixed in version 1.77-1. We recommend that you upgrade your transmission packages.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2010-0012
DSA-1967-1
Platform(s):Debian GNU/Linux 5.0
Product(s):transmission
Definition Synopsis
  • Debian GNU/Linux 5.0 is installed
  • AND Architecture section
  • Architecture independet section
  • Installed architecture is all
  • AND Packages section
  • transmission DPKG is earlier than 1.22-1+lenny2
  • OR transmission-common DPKG is earlier than 1.22-1+lenny2
  • OR transmission-gtk DPKG is earlier than 1.22-1+lenny2
  • OR transmission-cli DPKG is earlier than 1.22-1+lenny2
  • BACK