Transmission: Multiple vulnerabilities Stack-based buffer overflows in Transmission may allow for remote execution of arbitrary code. transmission 2010-06-01 2010-06-01 309831 remote 1.92 1.92

Transmission is a cross-platform BitTorrent client.

Multiple stack-based buffer overflows in the tr_magnetParse() function in libtransmission/magnet.c have been discovered.

A remote attacker could cause a Denial of Service or possibly execute arbitrary code via a crafted magnet URL with a large number of tr or ws links.

There is no known workaround at this time.

All Transmission users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-p2p/transmission-1.92"
CVE-2010-1853 craig keytoaster vorlon