Debian Security Update DSA-4650 qbittorrent - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,879
Reaction score
74
Credits
-1,257
Miguel Onoro reported that qbittorrent, a bittorrent client with a Qt5 GUI user interface, allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, which could result in remote command execution via a crafted name within an RSS feed if qbittorrent is configured to run an external program on torrent completion.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Latest posts

Top