CVE-2008-0646

The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service (stack exhaustion and crash) via a crafted bencoded message.
References
Link Resource
http://deluge-torrent.org/Changelog.php
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968 Exploit
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968
http://secunia.com/advisories/28699 Vendor Advisory
http://secunia.com/advisories/28700
http://secunia.com/advisories/28781 Vendor Advisory
http://secunia.com/advisories/28782
http://www.securityfocus.com/bid/27597 Patch
http://www.vupen.com/english/advisories/2008/0383
http://www.vupen.com/english/advisories/2008/0384
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html
http://deluge-torrent.org/Changelog.php
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968 Exploit
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968
http://secunia.com/advisories/28699 Vendor Advisory
http://secunia.com/advisories/28700
http://secunia.com/advisories/28781 Vendor Advisory
http://secunia.com/advisories/28782
http://www.securityfocus.com/bid/27597 Patch
http://www.vupen.com/english/advisories/2008/0383
http://www.vupen.com/english/advisories/2008/0384
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:deluge_team:deluge:*:*:*:*:*:*:*:*
cpe:2.3:a:rasterbar_software:libtorrent:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:42

Type Values Removed Values Added
References () http://deluge-torrent.org/Changelog.php - () http://deluge-torrent.org/Changelog.php -
References () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968 - Exploit () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968 - Exploit
References () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968 - () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968 -
References () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968 - () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968 -
References () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968 - () http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968 -
References () http://secunia.com/advisories/28699 - Vendor Advisory () http://secunia.com/advisories/28699 - Vendor Advisory
References () http://secunia.com/advisories/28700 - () http://secunia.com/advisories/28700 -
References () http://secunia.com/advisories/28781 - Vendor Advisory () http://secunia.com/advisories/28781 - Vendor Advisory
References () http://secunia.com/advisories/28782 - () http://secunia.com/advisories/28782 -
References () http://www.securityfocus.com/bid/27597 - Patch () http://www.securityfocus.com/bid/27597 - Patch
References () http://www.vupen.com/english/advisories/2008/0383 - () http://www.vupen.com/english/advisories/2008/0383 -
References () http://www.vupen.com/english/advisories/2008/0384 - () http://www.vupen.com/english/advisories/2008/0384 -
References () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html - () https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html -

Information

Published : 2008-02-07 21:00

Updated : 2024-11-21 00:42


NVD link : CVE-2008-0646

Mitre link : CVE-2008-0646

CVE.ORG link : CVE-2008-0646


JSON object : View

Products Affected

deluge_team

  • deluge

rasterbar_software

  • libtorrent
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer