From 3cf7c3ef441822c889356fd1812ebf2944a59851 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 25 Aug 2020 10:45:55 +0100 Subject: gentoo resync : 25.08.2020 --- metadata/glsa/glsa-202007-07.xml | 51 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 metadata/glsa/glsa-202007-07.xml (limited to 'metadata/glsa/glsa-202007-07.xml') diff --git a/metadata/glsa/glsa-202007-07.xml b/metadata/glsa/glsa-202007-07.xml new file mode 100644 index 000000000000..3093043f627d --- /dev/null +++ b/metadata/glsa/glsa-202007-07.xml @@ -0,0 +1,51 @@ + + + + Transmission: Remote code execution + A use-after-free possibly allowing remote execution of code was + discovered in Transmission. + + transmission + 2020-07-26 + 2020-07-26 + 723258 + remote + + + 3.00 + 3.00 + + + +

Transmission is a cross-platform BitTorrent client.

+
+ +

Transmission mishandles some memory management which may allow + manipulation of the heap. +

+
+ +

A remote attacker could entice a user to open a specially crafted + torrent file using Transmission, possibly resulting in execution of + arbitrary code with the privileges of the process or a Denial of Service + condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All Transmission users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=net-p2p/transmission-3.00" + + +
+ + CVE-2018-10756 + + sam_c + sam_c +
-- cgit v1.2.3