• [SECURITY] [DSA 4650-1] qbittorrent security update

    From Salvatore Bonaccorso@1:229/2 to All on Thu Apr 2 23:00:01 2020
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-4650-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    April 02, 2020 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : qbittorrent
    CVE ID : CVE-2019-13640
    Debian Bug : 932539

    Miguel Onoro reported that qbittorrent, a bittorrent client with a Qt5
    GUI user interface, allows command injection via shell metacharacters in
    the torrent name parameter or current tracker parameter, which could
    result in remote command execution via a crafted name within an RSS feed
    if qbittorrent is configured to run an external program on torrent
    completion.

    For the oldstable distribution (stretch), this problem has been fixed
    in version 3.3.7-3+deb9u1.

    For the stable distribution (buster), this problem has been fixed in
    version 4.1.5-1+deb10u1.

    We recommend that you upgrade your qbittorrent packages.

    For the detailed security status of qbittorrent please refer to its
    security tracker page at: https://security-tracker.debian.org/tracker/qbittorrent

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl6GTpBfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Txwg/+I2tAvqqhct6WQO6WmFiiZJ4oSln/T6mD7Te8uQ1CPNntPShgqEYkOhdq 3sm103nYeeMMsSXLCUss7uSIvkrhyfxMUZF4VkfVMVVn/knK5YHuQgFcyQ98K+zL rLL2tJyA6Dm/0i+qdqYemu9wW6NiCOTDom4QO/eY18Z3nlNBFWMl70QfOxruCPb0 ffWHW9SG4wZpiEBJ+b4IKQ3Id4i6+ySEHKTKiO5tuKnctaXTYE+6gTyZ3GsrEhyN snHl8R8i4CwZ5Depd0O1H3LXnuJaoeRP25yW8uAmoUeK1QlKiao6PoKx3VGSpRWa +jSWSB/02pyR/ackPcwJW8ZwceMjidoKQ5j+89Zw//GA0bDjj+xYtTSTgGDfs2t+ qbBWOaI8F8g45bzZobYdZ9ETG3wHP8pj+t5/ewaLgq6coNOoVbt+nolDS0jokOPp ad5DJH1ZdjrBnVlHD5d7F8qHVzZqPawSUqPb/KyRK0bGFVk355pAcp/sMjiIngGN PJtkr7u5ywrUWRuB+hy5AMLohCm8GIKFawJo4/179seWyv3awjrR3reZqN3kY0B3 NC1AI8As7mPRe6QtTa1GZeEBBUkK4U4yzItz8sIZTUdkmieRLFj9Ayo33sn2fw0M TiBEqokd1Galh5IiqbsytT52eEf48ymI+mHogwtk1tgM4SqFax8=
    =4BiN
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)