From 9df79f22ef726a6848aef487bb804ed8c7794f9a Mon Sep 17 00:00:00 2001 From: Thorsten Alteholz Date: Fri, 29 May 2020 11:02:02 +0200 Subject: DLA 2218 --- english/lts/security/2020/dla-2218.data | 10 ++++++++++ english/lts/security/2020/dla-2218.wml | 21 +++++++++++++++++++++ 2 files changed, 31 insertions(+) create mode 100644 english/lts/security/2020/dla-2218.data create mode 100644 english/lts/security/2020/dla-2218.wml diff --git a/english/lts/security/2020/dla-2218.data b/english/lts/security/2020/dla-2218.data new file mode 100644 index 00000000000..de1b96c523f --- /dev/null +++ b/english/lts/security/2020/dla-2218.data @@ -0,0 +1,10 @@ +DLA-2218-1 transmission +2020-5-24 +CVE-2018-10756 +transmission +yes +yes +no + +#use wml::debian::security + diff --git a/english/lts/security/2020/dla-2218.wml b/english/lts/security/2020/dla-2218.wml new file mode 100644 index 00000000000..b57cb2359e2 --- /dev/null +++ b/english/lts/security/2020/dla-2218.wml @@ -0,0 +1,21 @@ +LTS security update + + +

Tom Richards reported that by using a crafted torrent file one could cause +a use-after-free, which might result in a denial of service (crash) or +possible execution of arbitrary code.

+ + +

For Debian 8 Jessie, this problem has been fixed in version +2.84-0.2+deb8u2.

+ +

We recommend that you upgrade your transmission packages.

+ +

Further information about Debian LTS security advisories, how to apply +these updates to your system and frequently asked questions can be +found at: https://wiki.debian.org/LTS

+
+ +# do not modify the following line +#include "$(ENGLISHDIR)/lts/security/2020/dla-2218.data" +# $Id: $ -- cgit v1.2.3