CVE-2018-10756: Use After Free
Published May 15, 2020
·Updated
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
Affected Software
5 affected components
transmissionbt Transmission<3.00
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Remediation
Event History
May 15, 2020
CVE Published
via MITRE·03:56 PM
Data Sourced
via MITRE·03:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-10756.
2
What is the severity level of CVE-2018-10756?
The severity level of CVE-2018-10756 is high with a score of 7.8.
3
What is the affected software of CVE-2018-10756?
The affected software of CVE-2018-10756 includes Transmission before version 3.00, Debian Linux 8.0 and 9.0, and Fedora 31 and 32.
4
What is the impact of CVE-2018-10756?
CVE-2018-10756 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
5
How can I fix CVE-2018-10756?
To fix CVE-2018-10756, update Transmission to version 3.00 or later, or apply the necessary security patches provided by Debian or Fedora.