CVE-2008-0646
 
Severity Score
7.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service (stack exhaustion and crash) via a crafted bencoded message.
La función recursiva bdecode en include/libtorrent/bencode.hpp en Rasterbar Software libtorrent versiones anteriores a 0.12.1, usado en Deluge versiones anteriores a 0.5.8.3 y en otros productos, permite a atacantes según contexto provocar una denegación de servicio (agotamiento de pila y caída) a través de un mensaje bencoded manipulado.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-02-07 CVE Reserved
- 2008-02-07 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-11-03 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://deluge-torrent.org/Changelog.php | X_refsource_confirm | |
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?view=log&pathrev=1968#rev1968 | X_refsource_confirm | |
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_13/include/libtorrent/bencode.hpp?view=log&pathrev=1968 | X_refsource_confirm | |
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/trunk/include/libtorrent/bencode.hpp?view=log&pathrev=1968 | X_refsource_confirm | |
http://secunia.com/advisories/28700 | Third Party Advisory | |
http://secunia.com/advisories/28782 | Third Party Advisory | |
http://www.vupen.com/english/advisories/2008/0383 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/0384 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://libtorrent.svn.sourceforge.net/viewvc/libtorrent/branches/RC_0_12/include/libtorrent/bencode.hpp?r1=956&r2=1968&pathrev=1968 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/27597 | 2011-03-08 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/28699 | 2011-03-08 | |
http://secunia.com/advisories/28781 | 2011-03-08 | |
https://www.redhat.com/archives/fedora-package-announce/2008-February/msg00001.html | 2011-03-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Deluge Team Search vendor "Deluge Team" | Deluge Search vendor "Deluge Team" for product "Deluge" | <= 0.5.8.2 Search vendor "Deluge Team" for product "Deluge" and version " <= 0.5.8.2" | - |
Affected
| ||||||
Rasterbar Software Search vendor "Rasterbar Software" | Libtorrent Search vendor "Rasterbar Software" for product "Libtorrent" | <= 0.12 Search vendor "Rasterbar Software" for product "Libtorrent" and version " <= 0.12" | - |
Affected
|