ALAS-2020-1399


Amazon Linux 1 Security Advisory: ALAS-2020-1399
Advisory Release Date: 2020-07-14 02:15 Pacific
Advisory Updated Date: 2020-07-15 17:27 Pacific
Severity: Medium

Issue Overview:

Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file. (CVE-2018-10756)


Affected Packages:

transmission


Issue Correction:
Run yum update transmission to update your system.

New Packages:
i686:
    transmission-debuginfo-3.00-1.1.amzn1.i686
    transmission-3.00-1.1.amzn1.i686
    transmission-cli-3.00-1.1.amzn1.i686
    transmission-daemon-3.00-1.1.amzn1.i686
    transmission-common-3.00-1.1.amzn1.i686

src:
    transmission-3.00-1.1.amzn1.src

x86_64:
    transmission-3.00-1.1.amzn1.x86_64
    transmission-debuginfo-3.00-1.1.amzn1.x86_64
    transmission-daemon-3.00-1.1.amzn1.x86_64
    transmission-cli-3.00-1.1.amzn1.x86_64
    transmission-common-3.00-1.1.amzn1.x86_64