Mageia 2019-0379: qbittorrent security update
Summary
In qBittorrent before 4.1.7, the function Application::runExternalProgram()
located in app/application.cpp allows command injection via shell
metacharacters in the torrent name parameter or current tracker parameter, as
demonstrated by remote command execution via a crafted name within an RSS feed
(CVE-2019-13640).
The qbittorrent package has been updated to version 4.1.9.1, fixing this issue
and several others.
References
- https://bugs.mageia.org/show_bug.cgi?id=25507
- https://www.qbittorrent.org/news
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13640
Resolution
MGASA-2019-0379 - Updated qbittorrent packages fix security vulnerability
SRPMS
- 7/core/qbittorrent-4.1.9.1-1.mga7