Hash: SHA512

Package        : qbittorrent
Version        : 2.9.8-1+deb7u1
CVE ID         : CVE-2017-6503 CVE-2017-6504

CVE-2017-6503
      WebUI in qBittorrent before 3.3.11 did not escape many values,
      which could potentially lead to XSS.

CVE-2017-6504

      WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options
      header, which could potentially lead to clickjacking.

For Debian 7 "Wheezy", these problems have been fixed in version
2.9.8-1+deb7u1.

We recommend that you upgrade your qbittorrent packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-897-1: qbittorrent security update

April 16, 2017
CVE-2017-6503 WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS

Summary

CVE-2017-6504

WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options
header, which could potentially lead to clickjacking.

For Debian 7 "Wheezy", these problems have been fixed in version
2.9.8-1+deb7u1.

We recommend that you upgrade your qbittorrent packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : qbittorrent
Version : 2.9.8-1+deb7u1
CVE ID : CVE-2017-6503 CVE-2017-6504

Related News