The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.
References
Link | Resource |
---|---|
https://utclient.utorrent.com/offers/beta_release_notes/release_notes.html | Release Notes Vendor Advisory |
https://forum.utorrent.com/forum/13-announcements/ | Vendor Advisory |
https://twitter.com/va_start | Third Party Advisory |
https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-03-02 11:15
Updated : 2022-05-03 07:29
NVD link : CVE-2020-8437
Mitre link : CVE-2020-8437
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
bittorrent
- utorrent