drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in Transmission
Name: |
Ausführen beliebiger Kommandos in Transmission |
|
ID: |
DSA-4087-1 |
|
Distribution: |
Debian |
|
Plattformen: |
Debian jessie, Debian stretch |
|
Datum: |
So, 14. Januar 2018, 23:28 |
|
Referenzen: |
Keine Angabe |
|
Applikationen: |
Transmission |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512
- ------------------------------------------------------------------------- Debian Security Advisory DSA-4087-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 14, 2018 https://www.debian.org/security/faq - -------------------------------------------------------------------------
Package : transmission CVE ID : not yet available
Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.
For the oldstable distribution (jessie), this problem has been fixed in version 2.84-0.2+deb8u1.
For the stable distribution (stretch), this problem has been fixed in version 2.92-2+deb9u1.
We recommend that you upgrade your transmission packages.
For the detailed security status of transmission please refer to its security tracker page at: https://security-tracker.debian.org/tracker/transmission
Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlpboo0ACgkQEMKTtsN8 TjY/wg//WxYvh8ViFTrAIP4992q5Dc7zp7EoBRKQOvjA8NOQu4hW+vrteUERCaCf wv1amZTwY5eA+Tm8M5hzFZMudKVXS0Y2aZOC7AdIkIsq/g9w08eQMCR7Y5g2y/1z 6ubRwMXZLCEq4yI0HL6sAtPMFTl64nwBBv0bQ1X/I277/UPt6ejDVqd/XKSLr5qK lClTVXrFl1ILem7E4ZD0KFQU/VvoMr8awSvrdiCYs8lNYjw0XSmtO0OqKJICJ8tH 3txe9F3JhIbdPim3ZLrl1CHzXO32LNIdVlbCqrzva2YcchIACWmu9LBBEU3t4hb9 4Q7vnc6rHE3oNwhjEn5FM6IyWeLSf30l6usCaRg8+2uaDCKO+Ft6skvyaAtkpNK4 nrB1L1YvEEcpm5akby+kZDBH5AtKfLDkutTM8B64IKvIWKsLcD0PwbCtVa7rSPFP 7gPbsRZryHJHcSDHsfukTbJECuS8roYxsZBA11jSYcnIROcslwngCSyrGg3IxddP 8hXS9wwMUJpgca1qMiOG9XdA+la5YSybNfL/QPkU5dStVojlO7Vf16vLTI/nWf/M 8cse1Z+VKpK4PLQhdKTsPzYTm4TJaOJg08QnKpRkoWGVEVVC2rl/TV60DKr3NVcp yQ/4UXDQMXc1GhyyB4WX19JAnbjymL8Fp1yU7ggbvy/3FP4J1FU= =dmU3 -----END PGP SIGNATURE-----
|
|
|
|