Bug 1118290 (CVE-2014-4909)

Summary: CVE-2014-4909 transmission: peer communication vulnerability
Product: [Other] Security Response Reporter: Vasyl Kaigorodov <vkaigoro>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: abdulkarimmemon, admiller, carnil, charles, jspaleta, kumarpraveen.nitdgp, metherid, raghusiddarth, sanjay.ankur, sasansiasati
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: transmission 2.84 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:33:58 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1118291, 1118292    
Bug Blocks:    

Description Vasyl Kaigorodov 2014-07-10 11:48:04 UTC
Transmission version 2.84 fixes peer communication vulnerability (no known exploits) reported by Ben Hawkes.

Changelog: http://trac.transmissionbt.com/wiki/Changes#version-2.84
More technical details available in the Gentoo bugtracker:
https://bugs.gentoo.org/show_bug.cgi?id=516822

Comment 1 Vasyl Kaigorodov 2014-07-10 11:48:28 UTC
Created transmission tracking bugs for this issue:

Affects: fedora-all [bug 1118291]
Affects: epel-all [bug 1118292]

Comment 2 Vasyl Kaigorodov 2014-07-11 10:42:35 UTC
This seems likely to be about the below (possible exploit):

  http://inertiawar.com/submission.go
  http://twitter.com/benhawkes/statuses/484378151959539712 (2 Jul 2014)

Comment 3 Fedora Update System 2014-07-19 06:01:53 UTC
transmission-2.84-1.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Fedora Update System 2014-08-15 02:38:01 UTC
transmission-2.84-1.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Bam Bame 2019-04-07 06:24:24 UTC
hi there

Please Update Transmission on RHEL7 because there were some connectivity and stability issues that are solved on version 2.94 (May 1, 2018; 10 months ago), but there is no Update available yet!
so Please update this to 2.94 on RHEL7

regards

Comment 6 Product Security DevOps Team 2019-06-08 02:33:58 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.