BitTorrent Bootstrap 'Lazy _ bdecode. cpp 'Remote Code Execution Vulnerability
BitTorrent Bootstrap 'Lazy _ bdecode. cpp 'Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
BitTorrent
Description:
Bugtraq id: 76098
CVE (CAN) ID: CVE-2015-5685
BitTorrent Bootstrap is the guiding tool of the bit stream DHT network.
BitTorrent Bootstrap has a security vulnerability when processing parameters received by the lazy_bdecode function. Attackers can exploit this vulnerability to access data allocated to external connections and execute arbitrary code in the context of the current process.
<* Source: Team_LPJ @ BoB
Link: http://www.zerodayinitiative.com/advisories/ZDI-15-366/
*>
Suggestion:
Vendor patch:
BitTorrent
----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/bittorrent/bootstrap-dht/commit/e809ea80e3527e32c40756eddd8b2ae44bc3af1a
This article permanently updates the link address: