Vulnerability Description
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Transmissionbt | Transmission | < 3.00 |
| Debian | Debian Linux | 8.0 |
| Fedoraproject | Fedora | 31 |
Related Weaknesses (CWE)
References
- https://github.com/transmission/transmission/commit/2123adf8e5e1c2b48791f9d22fc8PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00022.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00001.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202007-07Third Party Advisory
- https://tomrichards.net/2020/05/cve-2018-10756-transmission/ExploitMitigationVendor Advisory
- https://github.com/transmission/transmission/commit/2123adf8e5e1c2b48791f9d22fc8PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00022.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00001.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202007-07Third Party Advisory
- https://tomrichards.net/2020/05/cve-2018-10756-transmission/ExploitMitigationVendor Advisory
FAQ
What is CVE-2018-10756?
CVE-2018-10756 is a vulnerability with a CVSS score of 7.8 (HIGH). Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
How severe is CVE-2018-10756?
CVE-2018-10756 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10756?
Check the references section above for vendor advisories and patch information. Affected products include: Transmissionbt Transmission, Debian Debian Linux, Fedoraproject Fedora.