DEBIAN-CVE-2025-54310

Source
https://security-tracker.debian.org/tracker/CVE-2025-54310
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54310.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-54310
Upstream
Published
2025-07-18T20:15:24Z
Modified
2026-09-01T20:05:54Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

qBittorrent before 5.1.2 does not prevent access to a local file that is referenced in a link URL. This affects rsswidget.cpp and searchjobwidget.cpp.

References

Affected packages

Debian:12 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/debian/qbittorrent?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.5.2-3
4.5.2-3+deb12u1
4.5.3-1
4.5.3-2
4.5.3-3
4.5.3-4
4.5.4-1
4.5.5-1
4.6.0-1
4.6.1-1
4.6.1-2
4.6.2-1
4.6.2-2
4.6.2-3
4.6.3-1
4.6.4-1
4.6.4-2
4.6.4-3
4.6.5-1
4.6.6-1
4.6.7-1
5.*
5.0.0-1
5.0.1-1
5.0.2-1
5.0.3-1
5.0.3-2
5.0.4-1
5.0.5-1
5.1.0-1
5.1.0-2
5.1.2-1~bpo13+1
5.1.2-1
5.1.3-1
5.1.4-1~bpo13+1
5.1.4-dmo1
5.2.0-1
5.2.0-2
5.2.1-1
5.2.2-1
5.2.3-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54310.json"

Debian:13 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/debian/qbittorrent?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.1.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54310.json"

Debian:14 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/debian/qbittorrent?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
5.1.0-2

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-54310.json"