CVE-2014-4909

UnknownEPSS 5.41%

Last modified

CVE-2014-4909 is a vulnerability of currently unknown severity. Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.. EPSS estimates a 5.41% chance of exploitation in the next 30 days.

Description

Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.

Metrics

EPSS Probability
5.41%

91.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux13.10
CanonicalUbuntu Linux14.04
FedoraprojectFedora20
GentooLinuxAll versions
TransmissionbtTransmission<= 2.83
TransmissionbtTransmission0.1
TransmissionbtTransmission0.2
TransmissionbtTransmission0.3
TransmissionbtTransmission0.4
TransmissionbtTransmission0.5
TransmissionbtTransmission0.6
TransmissionbtTransmission0.6.1
TransmissionbtTransmission0.70
TransmissionbtTransmission0.71
TransmissionbtTransmission0.72
TransmissionbtTransmission0.80
TransmissionbtTransmission0.81
TransmissionbtTransmission0.82
TransmissionbtTransmission0.90
TransmissionbtTransmission0.91
TransmissionbtTransmission0.92
TransmissionbtTransmission0.93
TransmissionbtTransmission0.94
TransmissionbtTransmission0.95
TransmissionbtTransmission0.96
TransmissionbtTransmission1.00
TransmissionbtTransmission1.01
TransmissionbtTransmission1.02
TransmissionbtTransmission1.2
TransmissionbtTransmission1.03
TransmissionbtTransmission1.04
TransmissionbtTransmission1.05
TransmissionbtTransmission1.06
TransmissionbtTransmission1.10
TransmissionbtTransmission1.11
TransmissionbtTransmission1.20
TransmissionbtTransmission1.21
TransmissionbtTransmission1.22
TransmissionbtTransmission1.30
TransmissionbtTransmission1.31
TransmissionbtTransmission1.32
TransmissionbtTransmission1.33
TransmissionbtTransmission1.34
TransmissionbtTransmission1.40
TransmissionbtTransmission1.41
TransmissionbtTransmission1.42
TransmissionbtTransmission1.50
TransmissionbtTransmission1.51
TransmissionbtTransmission1.52

Showing 50 of 105 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-4909?
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
How severe is CVE-2014-4909?
Severity scoring for CVE-2014-4909 is pending analysis. The EPSS model estimates a 5.41% probability of exploitation in the next 30 days.
How do I fix CVE-2014-4909?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-4909?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST