Ubuntu Security Notice (C) 2010-2013 Canonical, Inc. / NASL script (C) 2010-2013 Tenable Network Security, Inc.
The remote Ubuntu host is missing one or more security-related patches.
It was discovered that the Transmission web interface was vulnerable
to cross-site request forgery (CSRF) attacks. If a user were tricked
into opening a specially crafted web page in a browser while
Transmission was running, an attacker could trigger commands in
Transmission. This issue affected Ubuntu 9.04. (CVE-2009-1757)
Dan Rosenberg discovered that Transmission did not properly perform
input validation when processing torrent files. If a user were tricked
into opening a crafted torrent file, an attacker could overwrite files
via directory traversal. (CVE-2010-0012).
Update the affected packages.
Risk factor :
Medium / CVSS Base Score : 6.8