CVE-2020-8437
high · 7.5The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.
7.5
CVSS
12.0%
EPSS (exploit prob.)
96th
EPSS percentile
2020-03-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-476
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| bittorrent | utorrent | <= 3.5.5 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html
- https://forum.utorrent.com/forum/13-announcements/
- https://twitter.com/va_start
- https://utclient.utorrent.com/offers/beta_release_notes/release_notes.html
- https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html
- https://forum.utorrent.com/forum/13-announcements/
- https://twitter.com/va_start
- https://utclient.utorrent.com/offers/beta_release_notes/release_notes.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-8437