Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2)...
Vulnerability Description
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0364
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/27321
- http://aluigi.org/poc/ruttorrent.zip
- http://secunia.com/advisories/28537
- http://secunia.com/advisories/28533
- http://www.securityfocus.com/archive/1/486426/100/0/threaded
- http://forum.utorrent.com/viewtopic.php?id=29330
- http://securityreason.com/securityalert/3554
- http://aluigi.altervista.org/adv/ruttorrent-adv.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39720
- http://download.utorrent.com/1.7.6/utorrent-1.7.6.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39719
More from bittorrent
View All →Affected Vendor
bittorrent
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.