SB2019103125 - Input validation error in Debian Linux
Published: October 31, 2019 Updated: August 8, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2010-0748)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
Remediation
Install update from vendor's website.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0748
- https://github.com/transmission/transmission/wiki/Release-Notes#transmission-192-20100314
- https://security-tracker.debian.org/tracker/CVE-2010-0748
- https://trac.transmissionbt.com/ticket/2965
- https://www.openwall.com/lists/oss-security/2010/04/01/9