Transmission: Remote code execution A vulnerability in Transmission could allow a remote attacker to execute arbitrary RPC commands. transmission 2018-06-20 2018-06-20 644406 remote 2.93 2.93

Transmission is a cross-platform BitTorrent client.

A vulnerability was discovered in how Transmission handles access control through the X-Transmission-Session-Id.

A remote attacker could execute arbitrary RFC commands or consequently conduct a DNS rebinding attack.

There is no known workaround at this time.

All Transmission users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-p2p/transmission-"
CVE-2018-5702 b-man irishluck83