Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Deluge
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Deluge
ID: openSUSE-SU-2017:1497-1
Distribution: SUSE
Plattformen: openSUSE Leap 42.2
Datum: Mi, 7. Juni 2017, 07:15
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7178
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9031
Applikationen: Deluge

Originalnachricht

   openSUSE Security Update: Security update for deluge
______________________________________________________________________________

Announcement ID: openSUSE-SU-2017:1497-1
Rating: important
References: #1039815 #1039958
Cross-References: CVE-2017-7178 CVE-2017-9031
Affected Products:
openSUSE Leap 42.2
______________________________________________________________________________

An update that fixes two vulnerabilities is now available.

Description:

This update for deluge fixes two security issues:

- CVE-2017-9031: A remote attacker may have used a directory traversal
vulnerability in the web interface (bsc#1039815)
- CVE-2017-7178: A remote attacher could have exploited a CSRF
vulnerability to trick a logged-in user to perform actions in the WebUI
(bsc#1039958)

In addition, deluge was updated to 1.3.15 with the following fixes and
changes:

- Core: Fix issues with displaying libtorrent-rasterbar single proxy.
- Core: Fix libtorrent-rasterbar 1.2 trackers crashing Deluge UIs.
- Core: Fix an error in torrent priorities causing file priority mismatch
in UIs.
- GtkUI: Fix column sort state not saved in Thinclient mode.
- GtkUI: Fix a connection manager error with malformed ip.
- GtkUI: Rename SystemTray/Indicator "Pause/Resume All" to
"Pause/Resume
Session".
- GtkUI: Workaround libtorrent-rasterbar single proxy by greying out
unused proxy types.
- Notification Plugin: Fix webui passing string for int port value.
- AutoAdd Plugin: Add WebUI preferences page detailing lack of
configuration via WebUI.
- Label Plugin: Add WebUI preferences page detailing how to configure
plugin.
- Core: Fix 'Too many files open' errors.
- Core: Add support for python-GeoIP for use with libtorrent 1.1.
- Core: Fix a single proxy entry being overwritten resulting in no proxy
set.
- UI: Add the tracker_status translation to UIs.
- GtkUI: Strip whitespace from infohash before checks.
- GtkUI: Add a missed feature autofill infohash entry from clipboard.
- WebUI: Backport bind interface option for server.
- ConsoleUI: Fix a decode error comparing non-ascii (str) torrent names.
- AutoAdd Plugin: Fixes for splitting magnets from file.
- Remove the duplicate magnet extension when splitting.
- Remove deluge-libtorrent-1.1-geoip.patch: fixed upstream.


Patch Instructions:

To install this openSUSE Security Update use YaST online_update.
Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2017-656=1

To bring your system up-to-date, use "zypper patch".


Package List:

- openSUSE Leap 42.2 (noarch):

deluge-1.3.15-3.3.1
deluge-lang-1.3.15-3.3.1


References:

https://www.suse.com/security/cve/CVE-2017-7178.html
https://www.suse.com/security/cve/CVE-2017-9031.html
https://bugzilla.suse.com/1039815
https://bugzilla.suse.com/1039958

--
To unsubscribe, e-mail: opensuse-security-announce+unsubscribe@opensuse.org
For additional commands, e-mail: opensuse-security-announce+help@opensuse.org
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung