SB2014071801 - Input validation error in transmission (Alpine package)
Published: July 18, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2014-4909)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=070e5a669e2afaf7b2c7ac7a5d408fc468f2bca8
- https://git.alpinelinux.org/aports/commit/?id=fbd855ae17992591de1013afb41d8d767efeeb23
- https://git.alpinelinux.org/aports/commit/?id=e42400dfa239e507c673fd2b9124177ccbc88e01
- https://git.alpinelinux.org/aports/commit/?id=9e78173b077357c8331fb963f1e4006ded4f988c