Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:28592
HistoryOct 01, 2012 - 12:00 a.m.

[USN-1584-1]Transmission vulnerability

2012-10-0100:00:00
vulners.com
31

==========================================================================
Ubuntu Security Notice USN-1584-1
September 26, 2012

transmission vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS

Summary:

Transmission could be made to expose sensitive information over the
network.

Software Description:

  • transmission: lightweight BitTorrent client

Details:

Justin C. Klein Keane discovered that the Transmission web client
incorrectly escaped certain strings. If a user were tricked into opening a
specially crafted torrent file, an attacker could possibly exploit this to
conduct cross-site scripting (XSS) attacks.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
transmission-common 2.51-0ubuntu1.1

After a standard system update you need to restart Transmission to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1584-1
CVE-2012-4037

Package Information:
https://launchpad.net/ubuntu/+source/transmission/2.51-0ubuntu1.1