Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 209892 - net-p2p/bittorrent Unicode Client info Remote DoS (CVE-2008-0364)
Summary: net-p2p/bittorrent Unicode Client info Remote DoS (CVE-2008-0364)
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard: B4 [upstream?]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-02-12 18:09 UTC by Robert Buchholz (RETIRED)
Modified: 2008-02-12 19:12 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-02-12 18:09:08 UTC
CVE-2008-0364 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0364):
  Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and
  earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows
  allows remote attackers to cause a denial of service (application crash) via
  a long Unicode string representing a client version identifier.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-02-12 18:12:02 UTC
The advisory and CVE entry states versions prior to 6.0 (including our 5.0.9) might also be affected. I could not reproduce this issue with the exploits included with the advisory.

Net-p2p, have you heard anything from upstream about this? Can you reproduce (maybe on x86)?
Comment 2 Raúl Porcel (RETIRED) gentoo-dev 2008-02-12 18:23:39 UTC
"on Windows allows remote attackers to cause a denial of service"

Windows only?
Comment 3 Raúl Porcel (RETIRED) gentoo-dev 2008-02-12 18:25:04 UTC
Oh well, bittorrent-6.0 is based on utorrent, and this looks like its from utorrent, so the linux version(at least 5.0.x) is not affected.
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-02-12 19:10:46 UTC
I understood that that "on Windows" part was related to utorrent, which is only available on Windows.

Luigis's advisory states: "Mac and Linux (both available only on BitTorrent) have
not been tested". I can't reproduce this here, maybe you can confirm this, too?
Comment 5 Robert Buchholz (RETIRED) gentoo-dev 2008-02-12 19:12:46 UTC
(In reply to comment #3)
> Oh well, bittorrent-6.0 is based on utorrent, and this looks like its from
> utorrent, so the linux version(at least 5.0.x) is not affected.

Ok, thanks for the clarification.