-
-
Notifications
You must be signed in to change notification settings - Fork 316
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] Critical qBittorrent RCE Vulnerability #1190
Comments
Hi there, and thanks for the issue report. Unfortunately this is not an issue for headless clients and we would hardly consider this bug critical. I understand the concern and the desire to upgrade. The Swizzin team has assessed the report and disagree with the level of concern that has been levied against older versions of qbittorrent at this time, especially the headless client on Linux:
Finally, the issue at play is a MITM attack and not a RCE. This has been miscategorized by the author of the article and has been spread online. Additionally, there are far more concerning reports to me of memory leaks in 5.0, which could be far worse than the implications of simply using RSS feeds at this time. The upgrade to qbittorrent will come at in due time; however it will not be rushed out due to fear mongering and sensationalized allegations against qbit, where the majority of concerns are currently moot. If you have any questions on the subject, please forward them to our discord for further discussion. |
Hello. What manipulations need to be done to update to 5.0. I get this error Ubuntu 24 |
Can you supply installer logs? There weren't actually any changes to the libtorrent compile in the changes. |
I get an error when trying to update from 4.6.7 to 5.0.1 /usr/include/c++/13/array:109:55: note: at offset [12, 20] into destination object ‘std::array<unsigned int, 5>::_M_elems’ of size 20 |
I have the same message in my compile logs and my build is fine. Can you supply more logs? You should be able to attach files to the issue |
After 6 unsuccessful update, as you can see in the log, I have Ubuntu 24 version C++ 13, I tried to update C++ 13 to the new version C++ 14. Now I ran box upgrade qbittorrent again and the installation was successful Thank you for your quick response, maybe this information will help in the future |
What happened?
as currently all qbittorrent versions from 3.2.1 to 5.0.0 are affected by a critical RCE vulnerability i wanted to ask if it would be possible to add newer versions to the repo or fix the vulnerability without updating qbittorrent.
https://cybersecuritynews.com/qbittorrent-rce-vulnerability/
Swizzin commit
a4062a1
What OS are you using?
Ubuntu 22.04 (Jammy)
What architecture is your OS?
amd64
Relevant logs and output
The text was updated successfully, but these errors were encountered: