BitTorrent Bootstrap 'Lazy _ bdecode. cpp 'Remote Code Execution Vulnerability
Release date:
Updated on:
Affected Systems:
Github BitTorrent Bootstrap
Description:
Bugtraq id: 70812
CVE (CAN) ID: CVE-2014-8509
BitTorrent Bootstrap is the guiding tool of the bit stream DHT network.
BitTorrent Bootstrap has a remote code execution vulnerability. Attackers can exploit this vulnerability to execute arbitrary code in affected processes. This vulnerability exists in the parameter values that process the lazy_bdecode function.
<* Source: Daejin Lee
Link: http://www.zerodayinitiative.com/advisories/ZDI-14-370/
*>
Suggestion:
Vendor patch:
Github
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/bittorrent/bootstrap-dht/commit/bbc0b7191e3f48461ca6e5b1b34bdf4b3f1e79a9
This article permanently updates the link address: