BitTorrent and uTorrent Peers Window Remote Code Execution Vulnerability
BID:27321
Info
BitTorrent and uTorrent Peers Window Remote Code Execution Vulnerability
| Bugtraq ID: | 27321 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0364 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2008 12:00AM |
| Updated: | Apr 16 2015 06:06PM |
| Credit: | Luigi Auriemma is credited with the discovery of this vulnerability. |
| Vulnerable: |
uTorrent uTorrent 1.7.5 uTorrent uTorrent 1.6.1 uTorrent uTorrent 1.6 BitTorrent BitTorrent 6.0 |
| Not Vulnerable: |
uTorrent uTorrent 1.7.6 BitTorrent BitTorrent 6.0.1 |
Discussion
BitTorrent and uTorrent Peers Window Remote Code Execution Vulnerability
BitTorrent and uTorrent are prone to a remote code-execution vulnerability because the applications fail to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application or to crash the affected application, denying service to legitimate users.
This issue affects the following versions:
BitTorrent 6.0
uTorrent 1.7.5
uTorrent 1.8-alpha-7834
Earlier versions may be affected as well.
UPDATE (January 24, 2008): This issue was originally documented as a denial-of-service issue, but reliable reports suggest that this issue can be exploited to execute arbitrary code.
BitTorrent and uTorrent are prone to a remote code-execution vulnerability because the applications fail to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of the application or to crash the affected application, denying service to legitimate users.
This issue affects the following versions:
BitTorrent 6.0
uTorrent 1.7.5
uTorrent 1.8-alpha-7834
Earlier versions may be affected as well.
UPDATE (January 24, 2008): This issue was originally documented as a denial-of-service issue, but reliable reports suggest that this issue can be exploited to execute arbitrary code.
Exploit / POC
BitTorrent and uTorrent Peers Window Remote Code Execution Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
References
BitTorrent and uTorrent Peers Window Remote Code Execution Vulnerability
References:
References:
- BitTorrent Homepage (BitTorrent)
- uTorrent Homepage (uTorrent )
- Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5 (Luigi Auriemma
) - Re: Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5 (Luigi Auriemma
)