PT-2009-4229 · Ctorrent · Enhanced Ctorrent+1

Michael Brooks

·

Published

2009-05-22

·

Updated

2017-09-29

·

CVE-2009-1759

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Enhanced CTorrent versions 3.3.2 and earlier CTorrent version 1.3.4
Description: The issue is related to a stack-based buffer overflow in the btFiles::BuildFromMI function, which can be triggered by a Torrent file containing a long path. This can cause a denial of service (crash) and potentially allow remote attackers to execute arbitrary code.
Recommendations: For Enhanced CTorrent versions 3.3.2 and earlier, consider updating to a newer version that addresses this issue. For CTorrent version 1.3.4, consider updating to a newer version that addresses this issue. As a temporary workaround, consider restricting the handling of Torrent files with long paths to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1759
DSA-1817-1

Affected Products

Ctorrent
Enhanced Ctorrent