First published: Mon Feb 11 2013(Updated: )
A stack-based buffer overflow flaw was found in the way Transmission, a free, lightweight BitTorrent client, performed connection acknowledgements processing. A remote attacker could issue a specially-crafted request that, when processed would lead to transmission-daemon crash. Upstream ticket: [1] <a href="https://trac.transmissionbt.com/ticket/5002">https://trac.transmissionbt.com/ticket/5002</a> Source of the problem: [2] <a href="https://trac.transmissionbt.com/ticket/5002#comment:22">https://trac.transmissionbt.com/ticket/5002#comment:22</a> Libutp patches: [3] <a href="https://github.com/bittorrent/libutp/issues/38">https://github.com/bittorrent/libutp/issues/38</a> [4] <a href="https://github.com/bittorrent/libutp/issues/37">https://github.com/bittorrent/libutp/issues/37</a> Relevant transmission upstream patch: [5] <a href="https://trac.transmissionbt.com/changeset/13646">https://trac.transmissionbt.com/changeset/13646</a> Other references: [6] <a href="http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700234">http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=700234</a> [7] <a href="http://www.openwall.com/lists/oss-security/2013/02/10/2">http://www.openwall.com/lists/oss-security/2013/02/10/2</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Transmissionbt Transmission | <=2.73 | |
Transmissionbt Transmission | =0.1 | |
Transmissionbt Transmission | =0.2 | |
Transmissionbt Transmission | =0.3 | |
Transmissionbt Transmission | =0.4 | |
Transmissionbt Transmission | =0.5 | |
Transmissionbt Transmission | =0.6 | |
Transmissionbt Transmission | =0.6.1 | |
Transmissionbt Transmission | =0.70 | |
Transmissionbt Transmission | =0.71 | |
Transmissionbt Transmission | =0.72 | |
Transmissionbt Transmission | =0.80 | |
Transmissionbt Transmission | =0.81 | |
Transmissionbt Transmission | =0.82 | |
Transmissionbt Transmission | =0.90 | |
Transmissionbt Transmission | =0.91 | |
Transmissionbt Transmission | =0.92 | |
Transmissionbt Transmission | =0.93 | |
Transmissionbt Transmission | =0.94 | |
Transmissionbt Transmission | =0.95 | |
Transmissionbt Transmission | =0.96 | |
Transmissionbt Transmission | =1.00 | |
Transmissionbt Transmission | =1.01 | |
Transmissionbt Transmission | =1.02 | |
Transmissionbt Transmission | =1.2 | |
Transmissionbt Transmission | =1.03 | |
Transmissionbt Transmission | =1.04 | |
Transmissionbt Transmission | =1.05 | |
Transmissionbt Transmission | =1.06 | |
Transmissionbt Transmission | =1.10 | |
Transmissionbt Transmission | =1.11 | |
Transmissionbt Transmission | =1.20 | |
Transmissionbt Transmission | =1.21 | |
Transmissionbt Transmission | =1.22 | |
Transmissionbt Transmission | =1.30 | |
Transmissionbt Transmission | =1.31 | |
Transmissionbt Transmission | =1.32 | |
Transmissionbt Transmission | =1.33 | |
Transmissionbt Transmission | =1.34 | |
Transmissionbt Transmission | =1.40 | |
Transmissionbt Transmission | =1.41 | |
Transmissionbt Transmission | =1.42 | |
Transmissionbt Transmission | =1.50 | |
Transmissionbt Transmission | =1.51 | |
Transmissionbt Transmission | =1.52 | |
Transmissionbt Transmission | =1.53 | |
Transmissionbt Transmission | =1.54 | |
Transmissionbt Transmission | =1.60 | |
Transmissionbt Transmission | =1.61 | |
Transmissionbt Transmission | =1.70 | |
Transmissionbt Transmission | =1.71 | |
Transmissionbt Transmission | =1.72 | |
Transmissionbt Transmission | =1.73 | |
Transmissionbt Transmission | =1.74 | |
Transmissionbt Transmission | =1.75 | |
Transmissionbt Transmission | =1.76 | |
Transmissionbt Transmission | =1.77 | |
Transmissionbt Transmission | =1.80 | |
Transmissionbt Transmission | =1.81 | |
Transmissionbt Transmission | =1.82 | |
Transmissionbt Transmission | =1.83 | |
Transmissionbt Transmission | =1.90 | |
Transmissionbt Transmission | =1.91 | |
Transmissionbt Transmission | =1.92 | |
Transmissionbt Transmission | =1.93 | |
Transmissionbt Transmission | =2.00 | |
Transmissionbt Transmission | =2.01 | |
Transmissionbt Transmission | =2.02 | |
Transmissionbt Transmission | =2.03 | |
Transmissionbt Transmission | =2.04 | |
Transmissionbt Transmission | =2.10 | |
Transmissionbt Transmission | =2.11 | |
Transmissionbt Transmission | =2.12 | |
Transmissionbt Transmission | =2.13 | |
Transmissionbt Transmission | =2.20 | |
Transmissionbt Transmission | =2.21 | |
Transmissionbt Transmission | =2.22 | |
Transmissionbt Transmission | =2.30 | |
Transmissionbt Transmission | =2.31 | |
Transmissionbt Transmission | =2.32 | |
Transmissionbt Transmission | =2.33 | |
Transmissionbt Transmission | =2.40 | |
Transmissionbt Transmission | =2.41 | |
Transmissionbt Transmission | =2.42 | |
Transmissionbt Transmission | =2.50 | |
Transmissionbt Transmission | =2.51 | |
Transmissionbt Transmission | =2.52 | |
Transmissionbt Transmission | =2.60 | |
Transmissionbt Transmission | =2.61 | |
Transmissionbt Transmission | =2.70 | |
Transmissionbt Transmission | =2.71 | |
Transmissionbt Transmission | =2.72 | |
Canonical Ubuntu Linux | =11.10 | |
Canonical Ubuntu Linux | =12.04 | |
Canonical Ubuntu Linux | =12.10 | |
Fedoraproject Fedora | =16 | |
redhat/transmission | <2.74 | 2.74 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.