MGASA-2024-0359

Source
https://advisories.mageia.org/MGASA-2024-0359.html
Import Source
https://advisories.mageia.org/MGASA-2024-0359.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0359
Published
2024-11-12T19:53:59Z
Modified
2026-04-16T04:21:44.553471Z
Summary
Updated qbittorrent packages fix security vulnerabilities
Details

qBittorrent, on all platforms, did not verify any SSL certificates in its DownloadManager class from 2010 until October 2024. If it failed to verify a cert, it simply logged an error and proceeded.

References
Credits

Affected packages

Mageia:9 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:rpm/mageia/qbittorrent?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.6.7-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2024-0359.json"