CVE-2012-4037
Publication date 15 August 2012
Last updated 24 July 2024
Ubuntu priority
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.
Status
Package | Ubuntu Release | Status |
---|---|---|
transmission | 12.04 LTS precise |
Fixed 2.51-0ubuntu1.1
|
11.10 oneiric |
Not affected
|
|
11.04 natty |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
8.04 LTS hardy | Ignored end of life |
Notes
Patch details
Package | Patch details |
---|---|
transmission |
References
Related Ubuntu Security Notices (USN)
- USN-1584-1
- Transmission vulnerability
- 26 September 2012