Fedora 41 : deluge (2025-d23a07ad00)

high Nessus Plugin ID 235686

Language:

Synopsis

The remote Fedora host is missing one or more security updates.

Description

The remote Fedora 41 host has a package installed that is affected by a vulnerability as referenced in the FEDORA-2025-d23a07ad00 advisory.

https://deluge.readthedocs.io/en/deluge-2.2.0/changelog.html

2.2.0 (2025-04-28)

Breaking changes

Removed Python 3.6 support (Python >= 3.7)

Core

Fix GHSL-2024-189 - insecure HTTP for new version check.

Fix alert handler segfault.

Add support for creating v2 torrents.

GTK UI

Fix changing torrent ownership.

Fix upper limit of upload/download in Add Torrent dialog.

Fix #3339 - Resizing window crashes with Piecesbar or Stats plugin.

Fix #3350 - Unable to use quick search.

Fix #3598 - Missing AppIndicator option in Preferences.

Set Appindicator as default for tray icon on Linux.

Add feature to switch between dark/light themes.

Web UI

Fix GHSL-2024-191 - potential flag endpoint path traversal.

Fix GHSL-2024-188 - js script dir traversal vulnerability.

Fix GHSL-2024-190 - insecure tracker icon endpoint.

Fix unable to stop daemon in connection manager.

Fix responsiveness to avoid Connection lost.

Add support for network interface name as well as IP address.

Add ability to change UI theme.

Console UI

Fix rm and move commands hanging when done.

Fix #3538 - Unable to add host in connection manager.

Disable interactive-mode on Windows.

UI library

Fix tracker icon display by converting to png format.

Fix splitting trackers by newline

Add clickable URLs for torrent comment and tracker status.

Label

Fix torrent deletion not removed from config.

Fix label display name in submenu.

AutoAdd

Fix #3515 - Torrent file decoding errors disabled watch folder.



Tenable has extracted the preceding description block directly from the Fedora security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected deluge package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2025-d23a07ad00

Plugin Details

Severity: High

ID: 235686

File Name: fedora_2025-d23a07ad00.nasl

Version: 1.1

Type: local

Agent: unix

Published: 5/11/2025

Updated: 5/11/2025

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:deluge, cpe:/o:fedoraproject:fedora:41

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 5/2/2025

Vulnerability Publication Date: 5/2/2025

Reference Information