LWN.net Logo

Advertisement

Front, Kernel, Security, Distributions, Development. See your byline here on LWN.net.

Advertise here

ctorrent: buffer overflow

Package(s):ctorrent CVE #(s):CVE-2009-1759
Created:June 18, 2009 Updated:August 25, 2009
Description: ctorrent has a buffer overflow vulnerability. From the Debian alert: Michael Brooks discovered that ctorrent, a text-mode bittorrent client, does not verify the length of file paths in torrent files. An attacker can exploit this via a crafted torrent that contains a long file path to execute arbitrary code with the rights of the user opening the file.
Alerts:
Fedora FEDORA-2009-8897 2009-08-25
Fedora FEDORA-2009-8969 2009-08-25
Debian DSA-1817-1 2009-06-17

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds