Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 239824 (CVE-2008-0071) - <=net-p2p/bittorrent-6.0.3 (build 8642) Stack-based buffer overflow via .torrent file (CVE-2008-4434) and DOS via HTTP (CVE-2008-0071)
Summary: <=net-p2p/bittorrent-6.0.3 (build 8642) Stack-based buffer overflow via .torr...
Status: RESOLVED INVALID
Alias: CVE-2008-0071
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B2 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-10-05 01:32 UTC by Stefan Behte (RETIRED)
Modified: 2008-10-19 11:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Stefan Behte (RETIRED) gentoo-dev Security 2008-10-05 01:32:42 UTC
CVE-2008-4434 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4434):
  Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and
  earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote
  attackers to cause a denial of service (crash) and possibly execute
  arbitrary code via a long Created By field in a .torrent file.

CVE-2008-0071 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0071):
  The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent
  before 1.8beta build 10524 allows remote attackers to cause a denial of
  Service (application crash) via an HTTP request with a malformed Range header.
Comment 1 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-05 01:36:49 UTC
POC for CVE-2008-0071:
http://www.securityfocus.com/bid/29661/exploit
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-05 01:45:59 UTC
It seems that 5.0.9 is the latest open source version. I'm trying to contact them.
Comment 3 Raúl Porcel (RETIRED) gentoo-dev 2008-10-05 09:23:55 UTC
Yeah, this only affects 6.0, which is based on utorrent, which only works on windows :P
Comment 4 Pierre-Yves Rofes (RETIRED) gentoo-dev 2008-10-09 21:42:39 UTC
ok, so I guess we can close as invalid :)
Comment 5 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-09 23:29:00 UTC
Raul, I'd have loved to get a source for that.
Isn't utorrent based on bittorrent and not the other way round?
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2008-10-10 08:30:41 UTC
(In reply to comment #5)
> Raul, I'd have loved to get a source for that.
> Isn't utorrent based on bittorrent and not the other way round?
> 

http://torrentfreak.com/utorrent-relaunched-as-official-bittorrent-client/
http://support.bittorrent.com/faq/bittorrent-software-client/what-are-bittorrent-6x-system-requirements

Enough? :)
Comment 7 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-10 13:13:20 UTC
Sure, thanks! :)