CVE-2009-1759

Stack-based buffer overflow in the btFiles::BuildFromMI function (trunk/btfiles.cpp) in Enhanced CTorrent (aka dTorrent) 3.3.2 and probably earlier, and CTorrent 1.3.4, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Torrent file containing a long path.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
rahuldtorrent
3.2.0
rahuldtorrent
3.3.0
rahuldtorrent
3.3.1
rahuldtorrent
3.3.2
rahulctorrent
1.3.4
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ctorrent
bookworm
1.3.4.dnh3.3.2-5
fixed
bullseye
1.3.4.dnh3.3.2-5
fixed
sid
1.3.4.dnh3.3.2-6
fixed
trixie
1.3.4.dnh3.3.2-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ctorrent
maverick
not-affected
lucid
not-affected
karmic
not-affected
jaunty
ignored
intrepid
ignored
hardy
Fixed 1.3.4-dnh3.2-1+lenny1build0.8.04.1
released
dapper
dne
References