Google discovers uTorrent security vulnerabilities, and BitTorrent releases useless Patches

Source: Internet
Author: User

Google discovers uTorrent security vulnerabilities, and BitTorrent releases useless Patches

As early as January this year, Google Project Zero researcher Tavis Ormandy disclosed a vulnerability in BitTorrent application transmission and explained that other clients may have similar problems.

In a new report this week, Ormandy found similar security vulnerabilities in uTorrent, one of the most popular BitTorrent clients.

This issue was reported to BitTorrent in May, but the parent company failed to release patches in the 90-day window, as security researchers predicted, to solve the bugs found in the Project Zero Project, the relevant details are published this week.

This vulnerability exists in the Web interface, allowing users to remotely control the BitTorrent client. If exploited, it may allow attackers to control vulnerable computers.

The vulnerability is not fixed in the latest beta version.

However, the developing company said it had prepared a patch, which is part of the latest beta version, according to a report from torw.freak, it is expected to push to a stable channel as soon as possible this week.

However, it turns out that the patches shared with Ormandy will only make the original vulnerabilities useless and cannot completely solve the vulnerabilities.

"It looks like BitTorrent only adds a second token to uTorrent Web. This does not solve the DNS rebinding problem, but it just breaks my exploitation, "Ormandy explained on Twitter. "It just fixes the vulnerability and verifies that it is still valid. If you are affected, we recommend that you enable BitTorrent to solve this problem, and it works under the default configuration, so you may. "

BitTorrent has not provided an update statement to share new details about how and when to release a new patch. However, the company has published vulnerability information and should do so as soon as possible. The latest uTorrent update was released to version 3.5.3 Build February 17 Beta on April 9, 44352. The latest stable update date is August 1, December 24-version 3.5.1 Build 44332.

This article permanently updates link: https://www.bkjia.com/Linux/2018-02/151030.htm

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.