Lucene search

K
cveMitreCVE-2014-4909
HistoryJul 29, 2014 - 2:55 p.m.

CVE-2014-4909

2014-07-2914:55:07
CWE-189
mitre
web.nvd.nist.gov
41
cve-2014-4909
integer overflow
tr_bitfieldensurenthbitalloced function
bitfield.c
transmission
denial of service
execute arbitrary code

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.037

Percentile

91.9%

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

Affected configurations

Nvd
Node
canonicalubuntu_linuxMatch12.04-lts
OR
canonicalubuntu_linuxMatch13.10
OR
canonicalubuntu_linuxMatch14.04lts
OR
fedoraprojectfedoraMatch20
OR
gentoolinux
Node
transmissionbttransmissionRange2.83
OR
transmissionbttransmissionMatch0.1
OR
transmissionbttransmissionMatch0.2
OR
transmissionbttransmissionMatch0.3
OR
transmissionbttransmissionMatch0.4
OR
transmissionbttransmissionMatch0.5
OR
transmissionbttransmissionMatch0.6
OR
transmissionbttransmissionMatch0.6.1
OR
transmissionbttransmissionMatch0.70
OR
transmissionbttransmissionMatch0.71
OR
transmissionbttransmissionMatch0.72
OR
transmissionbttransmissionMatch0.80
OR
transmissionbttransmissionMatch0.81
OR
transmissionbttransmissionMatch0.82
OR
transmissionbttransmissionMatch0.90
OR
transmissionbttransmissionMatch0.91
OR
transmissionbttransmissionMatch0.92
OR
transmissionbttransmissionMatch0.93
OR
transmissionbttransmissionMatch0.94
OR
transmissionbttransmissionMatch0.95
OR
transmissionbttransmissionMatch0.96
OR
transmissionbttransmissionMatch1.00
OR
transmissionbttransmissionMatch1.01
OR
transmissionbttransmissionMatch1.02
OR
transmissionbttransmissionMatch1.2
OR
transmissionbttransmissionMatch1.03
OR
transmissionbttransmissionMatch1.04
OR
transmissionbttransmissionMatch1.05
OR
transmissionbttransmissionMatch1.06
OR
transmissionbttransmissionMatch1.10
OR
transmissionbttransmissionMatch1.11
OR
transmissionbttransmissionMatch1.20
OR
transmissionbttransmissionMatch1.21
OR
transmissionbttransmissionMatch1.22
OR
transmissionbttransmissionMatch1.30
OR
transmissionbttransmissionMatch1.31
OR
transmissionbttransmissionMatch1.32
OR
transmissionbttransmissionMatch1.33
OR
transmissionbttransmissionMatch1.34
OR
transmissionbttransmissionMatch1.40
OR
transmissionbttransmissionMatch1.41
OR
transmissionbttransmissionMatch1.42
OR
transmissionbttransmissionMatch1.50
OR
transmissionbttransmissionMatch1.51
OR
transmissionbttransmissionMatch1.52
OR
transmissionbttransmissionMatch1.53
OR
transmissionbttransmissionMatch1.54
OR
transmissionbttransmissionMatch1.60
OR
transmissionbttransmissionMatch1.61
OR
transmissionbttransmissionMatch1.70
OR
transmissionbttransmissionMatch1.71
OR
transmissionbttransmissionMatch1.72
OR
transmissionbttransmissionMatch1.73
OR
transmissionbttransmissionMatch1.74
OR
transmissionbttransmissionMatch1.75
OR
transmissionbttransmissionMatch1.76
OR
transmissionbttransmissionMatch1.77
OR
transmissionbttransmissionMatch1.80
OR
transmissionbttransmissionMatch1.81
OR
transmissionbttransmissionMatch1.82
OR
transmissionbttransmissionMatch1.83
OR
transmissionbttransmissionMatch1.90
OR
transmissionbttransmissionMatch1.91
OR
transmissionbttransmissionMatch1.92
OR
transmissionbttransmissionMatch1.93
OR
transmissionbttransmissionMatch2.00
OR
transmissionbttransmissionMatch2.01
OR
transmissionbttransmissionMatch2.02
OR
transmissionbttransmissionMatch2.03
OR
transmissionbttransmissionMatch2.04
OR
transmissionbttransmissionMatch2.10
OR
transmissionbttransmissionMatch2.11
OR
transmissionbttransmissionMatch2.12
OR
transmissionbttransmissionMatch2.13
OR
transmissionbttransmissionMatch2.20
OR
transmissionbttransmissionMatch2.21
OR
transmissionbttransmissionMatch2.22
OR
transmissionbttransmissionMatch2.30
OR
transmissionbttransmissionMatch2.31
OR
transmissionbttransmissionMatch2.32
OR
transmissionbttransmissionMatch2.33
OR
transmissionbttransmissionMatch2.40
OR
transmissionbttransmissionMatch2.41
OR
transmissionbttransmissionMatch2.42
OR
transmissionbttransmissionMatch2.50
OR
transmissionbttransmissionMatch2.51
OR
transmissionbttransmissionMatch2.52
OR
transmissionbttransmissionMatch2.60
OR
transmissionbttransmissionMatch2.61
OR
transmissionbttransmissionMatch2.70
OR
transmissionbttransmissionMatch2.71
OR
transmissionbttransmissionMatch2.72
OR
transmissionbttransmissionMatch2.73
OR
transmissionbttransmissionMatch2.74
OR
transmissionbttransmissionMatch2.75
OR
transmissionbttransmissionMatch2.76
OR
transmissionbttransmissionMatch2.77
OR
transmissionbttransmissionMatch2.80
OR
transmissionbttransmissionMatch2.81
OR
transmissionbttransmissionMatch2.82
VendorProductVersionCPE
canonicalubuntu_linux12.04cpe:2.3:o:canonical:ubuntu_linux:12.04:-:lts:*:*:*:*:*
canonicalubuntu_linux13.10cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
canonicalubuntu_linux14.04cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
fedoraprojectfedora20cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*
gentoolinux*cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
transmissionbttransmission*cpe:2.3:a:transmissionbt:transmission:*:*:*:*:*:*:*:*
transmissionbttransmission0.1cpe:2.3:a:transmissionbt:transmission:0.1:*:*:*:*:*:*:*
transmissionbttransmission0.2cpe:2.3:a:transmissionbt:transmission:0.2:*:*:*:*:*:*:*
transmissionbttransmission0.3cpe:2.3:a:transmissionbt:transmission:0.3:*:*:*:*:*:*:*
transmissionbttransmission0.4cpe:2.3:a:transmissionbt:transmission:0.4:*:*:*:*:*:*:*
Rows per page:
1-10 of 1051

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.7

Confidence

Low

EPSS

0.037

Percentile

91.9%