[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4650-1 qbittorrent -- qbittorrent

ID: oval:org.secpod.oval:def:604797Date: (C)2020-04-13   (M)2023-11-13
Class: PATCHFamily: unix




Miguel Onoro reported that qbittorrent, a bittorrent client with a Qt5 GUI user interface, allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, which could result in remote command execution via a crafted name within an RSS feed if qbittorrent is configured to run an external program on torrent completion.

Platform:
Debian 10.x
Debian 9.x
Product:
qbittorrent
Reference:
DSA-4650-1
CVE-2019-13640
CVE    1
CVE-2019-13640
CPE    3
cpe:/o:debian:debian_linux:10.x
cpe:/o:debian:debian_linux:9.x
cpe:/a:qbittorrent:qbittorrent

© SecPod Technologies