MGASA-2024-0359 - Updated qbittorrent packages fix security vulnerabilities

Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0359.html
Type: security
Affected Mageia releases: 9

qBittorrent, on all platforms, did not verify any SSL certificates in
its DownloadManager class from 2010 until October 2024.
If it failed to verify a cert, it simply logged an error and proceeded.

References:
- https://bugs.mageia.org/show_bug.cgi?id=33712
- https://www.openwall.com/lists/oss-security/2024/10/30/4
- https://www.openwall.com/lists/oss-security/2024/10/31/3

SRPMS:
- 9/core/qbittorrent-4.6.7-1.mga9

Mageia 2024-0359: qbittorrent Security Advisory Updates

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024

Summary

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References:

References

- https://bugs.mageia.org/show_bug.cgi?id=33712

- https://www.openwall.com/lists/oss-security/2024/10/30/4

- https://www.openwall.com/lists/oss-security/2024/10/31/3

Resolution

MGASA-2024-0359 - Updated qbittorrent packages fix security vulnerabilities

SRPMS

- 9/core/qbittorrent-4.6.7-1.mga9

Severity
Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0359.html
Type: security

Related News