It was discovered that Transmission incorrectly handled certain POST requests to the RPC server and allowed DNS rebinding attack. An attacker could possibly use this issue to execute arbitrary code.
{ "binaries": [ { "binary_name": "transmission", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-cli", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-cli-dbgsym", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-common", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-daemon", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-daemon-dbgsym", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-dbg", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-gtk", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-gtk-dbgsym", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-qt", "binary_version": "2.82-1.1ubuntu3.2" }, { "binary_name": "transmission-qt-dbgsym", "binary_version": "2.82-1.1ubuntu3.2" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "transmission", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-cli", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-cli-dbgsym", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-common", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-daemon", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-daemon-dbgsym", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-dbg", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-gtk", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-gtk-dbgsym", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-qt", "binary_version": "2.84-3ubuntu3.1" }, { "binary_name": "transmission-qt-dbgsym", "binary_version": "2.84-3ubuntu3.1" } ], "availability": "No subscription required" }