Debian Security Advisory
DSA-4087-1 transmission -- security update
- Date Reported:
- 14 Jan 2018
- Affected Packages:
- transmission
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 886990.
In Mitre's CVE dictionary: CVE-2018-5702. - More information:
-
Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.
For the oldstable distribution (jessie), this problem has been fixed in version 2.84-0.2+deb8u1.
For the stable distribution (stretch), this problem has been fixed in version 2.92-2+deb9u1.
We recommend that you upgrade your transmission packages.
For the detailed security status of transmission please refer to its security tracker page at: https://security-tracker.debian.org/tracker/transmission