CVE-2009-1759

Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.
References
Link Resource
http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&r2=301&view=patch Patch
http://secunia.com/advisories/34752 Vendor Advisory
http://secunia.com/advisories/35499
http://secunia.com/advisories/36471
http://sourceforge.net/tracker/?func=detail&aid=2782875&group_id=202532&atid=981959
http://www.debian.org/security/2009/dsa-1817
http://www.openwall.com/lists/oss-security/2009/05/20/3 Patch
http://www.securityfocus.com/bid/34584 Exploit Patch
http://www.vupen.com/english/advisories/2009/1092 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=501813
https://exchange.xforce.ibmcloud.com/vulnerabilities/49959
https://www.exploit-db.com/exploits/8470
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html
http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&r2=301&view=patch Patch
http://secunia.com/advisories/34752 Vendor Advisory
http://secunia.com/advisories/35499
http://secunia.com/advisories/36471
http://sourceforge.net/tracker/?func=detail&aid=2782875&group_id=202532&atid=981959
http://www.debian.org/security/2009/dsa-1817
http://www.openwall.com/lists/oss-security/2009/05/20/3 Patch
http://www.securityfocus.com/bid/34584 Exploit Patch
http://www.vupen.com/english/advisories/2009/1092 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=501813
https://exchange.xforce.ibmcloud.com/vulnerabilities/49959
https://www.exploit-db.com/exploits/8470
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rahul:dtorrent:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:rahul:dtorrent:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:rahul:dtorrent:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:rahul:dtorrent:3.3.2:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:rahul:ctorrent:1.3.4:*:*:*:*:*:*:*

History

21 Nov 2024, 01:03

Type Values Removed Values Added
References () http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&r2=301&view=patch - Patch () http://dtorrent.svn.sourceforge.net/viewvc/dtorrent/dtorrent/trunk/btfiles.cpp?r1=296&r2=301&view=patch - Patch
References () http://secunia.com/advisories/34752 - Vendor Advisory () http://secunia.com/advisories/34752 - Vendor Advisory
References () http://secunia.com/advisories/35499 - () http://secunia.com/advisories/35499 -
References () http://secunia.com/advisories/36471 - () http://secunia.com/advisories/36471 -
References () http://sourceforge.net/tracker/?func=detail&aid=2782875&group_id=202532&atid=981959 - () http://sourceforge.net/tracker/?func=detail&aid=2782875&group_id=202532&atid=981959 -
References () http://www.debian.org/security/2009/dsa-1817 - () http://www.debian.org/security/2009/dsa-1817 -
References () http://www.openwall.com/lists/oss-security/2009/05/20/3 - Patch () http://www.openwall.com/lists/oss-security/2009/05/20/3 - Patch
References () http://www.securityfocus.com/bid/34584 - Exploit, Patch () http://www.securityfocus.com/bid/34584 - Exploit, Patch
References () http://www.vupen.com/english/advisories/2009/1092 - Vendor Advisory () http://www.vupen.com/english/advisories/2009/1092 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=501813 - () https://bugzilla.redhat.com/show_bug.cgi?id=501813 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/49959 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/49959 -
References () https://www.exploit-db.com/exploits/8470 - () https://www.exploit-db.com/exploits/8470 -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01010.html -
References () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html - () https://www.redhat.com/archives/fedora-package-announce/2009-August/msg01102.html -

Information

Published : 2009-05-22 11:52

Updated : 2024-11-21 01:03


NVD link : CVE-2009-1759

Mitre link : CVE-2009-1759

CVE.ORG link : CVE-2009-1759


JSON object : View

Products Affected

rahul

  • ctorrent
  • dtorrent
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer