CVE Vulnerabilities

CVE-2014-4909

Published: Jul 29, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

Affected Software

NameVendorStart VersionEnd Version
Ubuntu_linuxCanonical12.04 (including)12.04 (including)
Ubuntu_linuxCanonical13.10 (including)13.10 (including)
Ubuntu_linuxCanonical14.04 (including)14.04 (including)
FedoraFedoraproject20 (including)20 (including)
LinuxGentoo**
TransmissionUbuntudevel*
TransmissionUbuntulucid*
TransmissionUbuntuprecise*
TransmissionUbuntusaucy*
TransmissionUbuntutrusty*
TransmissionUbuntuupstream*

References