libtorrent UPNP Port 0 Security Vulnerability
BID:68168
Info
libtorrent UPNP Port 0 Security Vulnerability
| Bugtraq ID: | 68168 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 14 2014 12:00AM |
| Updated: | Jun 14 2014 12:00AM |
| Credit: | leigh123linux |
| Vulnerable: |
Rasterbar Software libtorrent 0.16.11 |
| Not Vulnerable: | |
Discussion
libtorrent UPNP Port 0 Security Vulnerability
libtorrent is prone to a security vulnerability because fails to stop UPNP from opening port 0.
An attacker may exploit this issue to perform unauthorized actions in the context of the application. This may aid in other attacks.
libtorrent 0.16.11 is vulnerable; other versions may also be affected.
libtorrent is prone to a security vulnerability because fails to stop UPNP from opening port 0.
An attacker may exploit this issue to perform unauthorized actions in the context of the application. This may aid in other attacks.
libtorrent 0.16.11 is vulnerable; other versions may also be affected.
References
libtorrent UPNP Port 0 Security Vulnerability
References:
References:
- Fedora 20 Update: rb_libtorrent-0.16.11-2.fc20 (Fedora Project)
- libtorrent Home Page (Rasterbar Software)
- libtorrent-rasterbar new security issue due to UPNP port 0 (Mageia)
- UPNP opens port 0 which fully exposes PC to the internet (qBitTorrent)