>> uTorrent "created by" Field Handling Buffer Overflow Vulnerability
Title : uTorrent "created by" Field Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2008-2340 CVE ID : CVE-2008-4434 CWE ID : CWE-119
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-12
Technical Description
A vulnerability has been identified in uTorrent, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buffer overflow error when processing an overly long "created by" string in ".torrent" file, which could be exploited by attackers to execute arbitrary code by tricking a user into opening a malicious ".torrent" file.