Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 27 rb_libtorrent Security Advisory - Critical Heap Overflow

fedora
Calendar Grey December 3, 2017
Dist Fedora Esm H88
A serious heap overflow vulnerability in rb_libtorrent for Fedora 27 requires an urgent update to prevent potential code execution by attackers
Update to latest releases

Summary

rb_libtorrent is a C++ library that aims to be a good alternative to all

the other BitTorrent implementations around. It is a library and not a full

featured client, although it comes with a few working example clients.

Its main goals are to be very efficient (in terms of CPU and memory usage) as

well as being very easy to use both as a user and developer.

Update to latest releases

[ 1 ] Bug #1466432 - CVE-2017-9847 rb_libtorrent: Heap-buffer overflow in bdecode function [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1466432

[ 2 ] Bug #1438986 - rb_libtorrent-1.1.5 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1438986

[ 3 ] Bug #1516073 - qbittorrent-4.0.1 is available

https://bugzilla.redhat.com/show_bug.cgi?id=1516073

su -c 'dnf upgrade rb_libtorrent' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 1.1.5
Release: 1.fc27
Summary: A C++ BitTorrent library aiming to be the best alternative

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here