Vulnerability Description
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Deluge-Torrent | Deluge | < 1.3.14 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://dev.deluge-torrent.org/wiki/ReleaseNotes/1.3.14Release NotesVendor Advisory
- http://git.deluge-torrent.org/deluge/commit/?h=1.3-stable&id=318ab179865e0707d79PatchVendor Advisory
- http://git.deluge-torrent.org/deluge/commit/?h=develop&id=11e8957deaf0c76fdfbac6PatchVendor Advisory
- http://seclists.org/fulldisclosure/2017/Mar/6ExploitMailing ListPatch
- http://www.debian.org/security/2017/dsa-3856Third Party Advisory
- http://www.securityfocus.com/bid/97041Third Party AdvisoryVDB Entry
- https://bugs.debian.org/857903Third Party Advisory
- https://security.gentoo.org/glsa/201703-06Third Party Advisory
- http://dev.deluge-torrent.org/wiki/ReleaseNotes/1.3.14Release NotesVendor Advisory
- http://git.deluge-torrent.org/deluge/commit/?h=1.3-stable&id=318ab179865e0707d79PatchVendor Advisory
- http://git.deluge-torrent.org/deluge/commit/?h=develop&id=11e8957deaf0c76fdfbac6PatchVendor Advisory
- http://seclists.org/fulldisclosure/2017/Mar/6ExploitMailing ListPatch
- http://www.debian.org/security/2017/dsa-3856Third Party Advisory
- http://www.securityfocus.com/bid/97041Third Party AdvisoryVDB Entry
- https://bugs.debian.org/857903Third Party Advisory
FAQ
What is CVE-2017-7178?
CVE-2017-7178 is a vulnerability with a CVSS score of 8.8 (HIGH). CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causi...
How severe is CVE-2017-7178?
CVE-2017-7178 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7178?
Check the references section above for vendor advisories and patch information. Affected products include: Deluge-Torrent Deluge, Debian Debian Linux.