Debian Security Advisory
DLA-312-1 libtorrent-rasterbar -- LTS security update
- Date Reported:
- 20 Sep 2015
- Affected Packages:
- libtorrent-rasterbar
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 797046.
In Mitre's CVE dictionary: CVE-2015-5685. - More information:
-
The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."
Note while this CVE was reported against BitTorrent DHT Bootstrapt server, the same vulnerable code is available in libtorrent-rasterbar.