Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 00:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://forum.utorrent.com/viewtopic.php?id=44003 - | |
References | () http://lists.immunitysec.com/pipermail/dailydave/attachments/20080811/35d6194b/attachment-0001.pdf - | |
References | () http://seclists.org/dailydave/2008/q3/0155.html - | |
References | () http://secunia.com/advisories/31441 - Vendor Advisory | |
References | () http://secunia.com/advisories/31445 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/30653 - | |
References | () http://www.securitytracker.com/id?1020664 - | |
References | () http://www.vupen.com/english/advisories/2008/2340 - | |
References | () http://www.vupen.com/english/advisories/2008/2341 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/44404 - |
Information
Published : 2008-10-03 22:22
Updated : 2024-11-21 00:51
NVD link : CVE-2008-4434
Mitre link : CVE-2008-4434
CVE.ORG link : CVE-2008-4434
JSON object : View
Products Affected
bittorrent
- bittorrent
utorrent
- utorrent
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer