News Score: Score the News, Sort the News, Rewrite the Headlines

RCE Vulnerability in QBittorrent – Sharp Security

In qBittorrent, the DownloadManager class has ignored every SSL certificate validation error that has ever happened, on every platform, for 14 years and 6 months since April 6 2010 with commit 9824d86. The default behaviour changed to verifying on October 12 2024 with commit 3d9e971. The first patched release is version 5.0.1, released 2 days ago. The usages of DownloadManager across the program are extensive, and affect searches, .torrent downloads, RSS feeds, favicon downloads and more. All of...

Read more at sharpsec.run

© News Score  score the news, sort the news, rewrite the headlines