CVE Vulnerabilities

CVE-2014-4909

Published: Jul 29, 2014 | Modified: Nov 14, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

Affected Software

Name Vendor Start Version End Version
Ubuntu_linux Canonical 12.04 (including) 12.04 (including)
Ubuntu_linux Canonical 13.10 (including) 13.10 (including)
Ubuntu_linux Canonical 14.04 (including) 14.04 (including)
Fedora Fedoraproject 20 (including) 20 (including)
Linux Gentoo * *
Transmission Ubuntu devel *
Transmission Ubuntu lucid *
Transmission Ubuntu precise *
Transmission Ubuntu saucy *
Transmission Ubuntu trusty *
Transmission Ubuntu upstream *

References