Summary
The remote host is missing an update to transmission announced via advisory DSA 1967-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201967-1
Insight
Dan Rosenberg discovered that Transmission, a lightwight client for the Bittorrent filesharing protocol performs insufficient sanitising of file names specified in .torrent files. This could lead to the overwrite of local files with the privileges of the user running Transmission if the user is tricked into opening a malicious torrent file.
For the stable distribution (lenny), this problem has been fixed in version 1.22-1+lenny2.
For the unstable distribution (sid), this problem has been fixed in version 1.77-1.
We recommend that you upgrade your transmission packages.
Severity
Classification
-
CVE CVE-2010-0012 -
CVSS Base Score: 6.8
AV:N/AC:M/Au:N/C:P/I:P/A:P
Related Vulnerabilities