Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE 2023:0391-1 moderate: libtorrent and qbittorrent fix

opensuse
Calendar Grey December 7, 2023
Dist Opensuse Esm H88
Critical update released for openSUSE addressing a libtorrent and qbittorrent flaw labeled with ID 2023:0391-1.
An update that fixes one vulnerability is now available

Description

This update for libtorrent-rasterbar, qbittorrent fixes the following

issues:

Changes in libtorrent-rasterbar:

- Update to version 2.0.9

* fix issue with web seed connections when they close and re-open

* fallocate() not supported is not a fatal error

* fix proxying of IPv6 connections via IPv4 proxy

* treat CGNAT address range as local IPs

* add stricter checking of piece layers when loading torrents

* add stricter checking of v1 and v2 hashes being consistent

* cache failed DNS lookups as well as successful ones

* add an i2p torrent state to control interactions with clear swarms

* fix i2p SAM protocol parsing of quoted messages

* expose i2p peer destination in peer_info

* fix i2p tracker announces

* fix issue with read_piece() stopping torrent on pieces not yet

downloaded

* improve handling of allow_i2p_mixed setting to work for magnet links

* fix web seed request for renamed single-file...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2023-391=1

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-391=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

libtorrent-rasterbar-debuginfo-2.0.9-bp155.2.3.1

libtorrent-rasterbar-debugsource-2.0.9-bp155.2.3.1

libtorrent-rasterbar-devel-2.0.9-bp155.2.3.1

libtorrent-rasterbar2_0-2.0.9-bp155.2.3.1

libtorrent-rasterbar2_0-debuginfo-2.0.9-bp155.2.3.1

python3-libtorrent-rasterbar-2.0.9-bp155.2.3.1

python3-libtorrent-rasterbar-debuginfo-2.0.9-bp155.2.3.1

- openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64):

qbittorrent-4.6.2-bp155.2.3.1

qbittorrent-debuginfo-4.6.2-bp155.2.3.1

qbittorrent-debugsource-4.6.2-bp155.2.3.1

qbittorrent-nox-4.6.2-bp155.2.3.1

qbittorrent-nox-debuginfo-4.6.2-bp155.2.3.1

- openSUSE Backports SLE-15-SP5 (noarch):

libtorrent-rasterbar-doc-2.0.9-bp155.2.3.1

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

libtorrent-rasterbar-devel-2.0.9-bp154.3.3.1

libtorrent-rasterbar2_0-2.0.9-bp154.3.3.1

python3-libtorrent-rasterbar-2.0.9-bp154.3.3.1

qbittorrent-4.6.2-bp154.3.3.1

qbittorrent-debuginfo-4.6.2-bp154.3.3...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2023-30801.html

https://bugzilla.suse.com/1217677

Announcement ID: openSUSE-SU-2023:0391-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here