CVE-2014-4909

Publication date 11 July 2014

Last updated 24 July 2024


Ubuntu priority

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

Status

Package Ubuntu Release Status
transmission 14.04 LTS trusty
Fixed 2.82-1.1ubuntu3.1
13.10 saucy
Fixed 2.82-0ubuntu1.1
12.04 LTS precise
Fixed 2.51-0ubuntu1.4
10.04 LTS lucid Ignored end of life

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
transmission