Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.
http://www.vupen.com/english/advisories/2010/0655
http://www.securityfocus.com/bid/38814
http://trac.transmissionbt.com/wiki/Changes
http://trac.transmissionbt.com/ticket/2965