Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
21 Nov 2024, 03:41
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/transmission/transmission/commit/2123adf8e5e1c2b48791f9d22fc8c747e974180e - Patch, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/05/msg00022.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2020/08/msg00001.html - Mailing List, Third Party Advisory | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CD3GLZ5URIK74RCGLSH72IVLDIJJMLQC/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OVAG2HNKNRLWOACFN5F2ANJD2SQ53WI7/ - | |
References | () https://security.gentoo.org/glsa/202007-07 - Third Party Advisory | |
References | () https://tomrichards.net/2020/05/cve-2018-10756-transmission/ - Exploit, Mitigation, Vendor Advisory |
07 Nov 2023, 02:51
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-05-15 16:15
Updated : 2024-11-21 03:41
NVD link : CVE-2018-10756
Mitre link : CVE-2018-10756
CVE.ORG link : CVE-2018-10756
JSON object : View
Products Affected
debian
- debian_linux
fedoraproject
- fedora
transmissionbt
- transmission
CWE
CWE-416
Use After Free