Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 9: MGASA-2024-0359 critical: qBittorrent SSL validation flaw

mageia
Calendar Grey November 12, 2024
Dist Mageia Esm H88
The latest Mageia advisory points out vulnerabilities related to SSL certificates in qBittorrent which compromise security; fixes can be found in the updates.
qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024

Summary

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded. References:

References

- https://bugs.mageia.org/show_bug.cgi?id=33712

- https://www.openwall.com/lists/oss-security/2024/10/30/4

- https://www.openwall.com/lists/oss-security/2024/10/31/3

Resolution

SRPMS

- 9/core/qbittorrent-4.6.7-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0359.html
Type: security

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here