The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://forum.utorrent.com/forum/13-announcements/ | vendor advisory |
https://twitter.com/va_start | third party advisory |
https://utclient.utorrent.com/offers/beta_release_notes/release_notes.html | release notes vendor advisory |
https://blog.whtaguy.com/2020/09/utorrent-cve-2020-8437-vulnerability.html | third party advisory exploit |