Debian Security Advisory

DLA-312-1 libtorrent-rasterbar -- LTS security update

Date Reported:
20 Sep 2015
Affected Packages:
libtorrent-rasterbar
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 797046.
In Mitre's CVE dictionary: CVE-2015-5685.
More information:

The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."

Note while this CVE was reported against BitTorrent DHT Bootstrapt server, the same vulnerable code is available in libtorrent-rasterbar.