openSUSE-SU-2024:0358-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2024:0358-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2024:0358-1
Related
Published
2024-11-08T15:01:42Z
Modified
2024-11-08T15:01:42Z
Summary
Security update for qbittorrent
Details

This update for qbittorrent fixes the following issues:

  • Update to version 5.0.1 (fixes boo#1232731 CVE-2024-51774)

    Added features:

    • Add 'Simple pread/pwrite' disk IO type

    Bug fixes:

    • Don't ignore SSL errors (boo#1232731 CVE-2024-51774)
    • Don't try to apply Mark-of-the-Web to nonexistent files
    • Disable 'Move to trash' option by default
    • Disable the ability to create torrents with a piece size of 256MiB
    • Allow to choose Qt style
    • Always notify user about duplicate torrent
    • Correctly handle 'torrent finished after move' event
    • Correctly apply filename filter when !qB extension is enabled
    • Improve color scheme change detection
    • Fix button state for SSL certificate check

    Web UI:

    • Fix CSS that results in hidden torrent list in some browsers
    • Use proper text color to highlight items in all filter lists
    • Fix 'rename files' dialog cannot be opened more than once
    • Fix UI of Advanced Settings to show all settings
    • Free resources allocated by web session once it is destructed

    Search:

    • Import correct libraries

    Other changes:

    • Sync flag icons with upstream
References

Affected packages

SUSE:Package Hub 15 SP6 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:rpm/suse/qbittorrent&distro=SUSE%20Package%20Hub%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.1-bp156.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "qbittorrent-nox": "5.0.1-bp156.3.6.1",
            "qbittorrent": "5.0.1-bp156.3.6.1"
        }
    ]
}

openSUSE:Leap 15.6 / qbittorrent

Package

Name
qbittorrent
Purl
pkg:rpm/opensuse/qbittorrent&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.1-bp156.3.6.1

Ecosystem specific

{
    "binaries": [
        {
            "qbittorrent-nox": "5.0.1-bp156.3.6.1",
            "qbittorrent": "5.0.1-bp156.3.6.1"
        }
    ]
}