PT-2006-1411 · Bitcomet · Bitcomet Client+1

Fortinet Security Research

·

Publicado

2006-01-20

·

Atualizado

2018-10-19

·

CVE-2006-0339

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BitComet Client version 0.60
Description The issue allows remote attackers to execute arbitrary code when the publisher's name link is clicked, via a long publisher URI in a torrent file. This occurs because the BitComet Client fails to check the size of the publisher's name URI in a torrent file, resulting in a buffer overflow. With a specially crafted request, an attacker can execute arbitrary code, potentially resulting in a loss of availability.
Recommendations For BitComet Client version 0.60, consider disabling the handling of publisher's name links in torrent files until a patch is available to prevent arbitrary code execution. Restrict access to torrent files with long publisher URI to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0339

Produtos afetados

Bitcomet
Bitcomet Client