FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

libutp -- remote denial of service or arbitrary code execution

Affected packages
bittorrent-libutp < 0.20130514_1
transmission-cli < 2.74
transmission-deamon < 2.74
transmission-gtk < 2.74
transmission-qt4 < 2.74

Details

VuXML ID 0523fb7e-8444-4e86-812d-8de05f6f0dce
Discovery 2012-08-01
Entry 2014-12-29

NVD reports:

Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."

References

CVE Name CVE-2012-6129
URL https://github.com/bittorrent/libutp/issues/38
URL https://trac.transmissionbt.com/ticket/5002