← All CVEs

CVE-2008-4434

high · 9.3

Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.

9.3
CVSS
11.0%
EPSS (exploit prob.)
96th
EPSS percentile
2008-10-03
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
utorrentutorrent<= 1.7.7
utorrentutorrent1.1.1
utorrentutorrent1.1.3
utorrentutorrent1.1.4
utorrentutorrent1.1.5
utorrentutorrent1.1.6
utorrentutorrent1.1.7
utorrentutorrent1.2
utorrentutorrent1.2.1
utorrentutorrent1.2.2
utorrentutorrent1.3
utorrentutorrent1.4
utorrentutorrent1.4.2
utorrentutorrent1.5
utorrentutorrent1.6
utorrentutorrent1.7
utorrentutorrent1.7.1
utorrentutorrent1.7.2
utorrentutorrent1.7.3
utorrentutorrent1.7.4
utorrentutorrent1.7.5
utorrentutorrent1.7.6
bittorrentbittorrent<= 6.0.3
bittorrentbittorrent3.9.1
bittorrentbittorrent4.0.0
bittorrentbittorrent4.0.1
bittorrentbittorrent4.0.2
bittorrentbittorrent4.0.3
bittorrentbittorrent4.0.4
bittorrentbittorrent4.1.0
bittorrentbittorrent4.1.1
bittorrentbittorrent4.1.2
bittorrentbittorrent4.1.3
bittorrentbittorrent4.1.4
bittorrentbittorrent4.1.5
bittorrentbittorrent4.1.6
bittorrentbittorrent4.1.7
bittorrentbittorrent4.1.8
bittorrentbittorrent4.2.0
bittorrentbittorrent4.2.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-4434