[Full-disclosure] Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5

Luigi Auriemma aluigi at autistici.org
Fri Jan 25 19:42:50 GMT 2008


Secunia has made additional research on the vulnerability I reported a
week ago about the buffer-overflow in uTorrent and has found that remote
code execution is possible.

That's important moreover because in the moment I'm writing there are
still tons of people which use the 1.7.5 or other vulnerables 1.7.x
versions of uTorrent.

Then some days ago has been released BitTorrent 6.0.1 which fixes the
vulnerability in this client too.


--- 
Luigi Auriemma
http://aluigi.org




Full-Disclosure is hosted and sponsored by Secunia.