UBUNTU-CVE-2017-12778

Source
https://ubuntu.com/security/CVE-2017-12778
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2017-12778
Withdrawn
2025-06-23T15:52:59Z
Published
2019-05-09T17:29:00Z
Modified
2019-05-09T17:29:00Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

** DISPUTED ** The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file at the C:\Users<username>\Roaming\qBittorrent pathname. The attacker must change the value of the "locked" attribute to "false" within the "Locking" stanza. NOTE: This is an intended behavior. See https://github.com/qbittorrent/qBittorrent/wiki/I-forgot-my-UI-lock-password.

References

Affected packages

Ubuntu:Pro:16.04:LTS / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/ubuntu/qbittorrent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.2.3-2
3.2.5-1
3.3.1-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json"

Ubuntu:Pro:18.04:LTS / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/ubuntu/qbittorrent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.3.7-3
3.3.15-1
4.*
4.0.3-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json"

Ubuntu:20.04:LTS / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/ubuntu/qbittorrent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.1.7-1
4.1.7-1ubuntu2
4.1.7-1ubuntu3

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json"

Ubuntu:22.04:LTS / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/ubuntu/qbittorrent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.2.5-0.1ubuntu1
4.2.5-0.1ubuntu2
4.3.9-1
4.3.9-2
4.4.0-1
4.4.0-2
4.4.1-2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json"

Ubuntu:24.04:LTS / qbittorrent

Package

Name
qbittorrent
Purl
pkg:deb/ubuntu/qbittorrent

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.5.4-1
4.6.0-1
4.6.1-1
4.6.1-2
4.6.2-1
4.6.2-2
4.6.2-3
4.6.3-1
4.6.3-1build1
4.6.3-1build2

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2017/UBUNTU-CVE-2017-12778.json"