CVE-2008-4434

Utorrent < 1.7.7 - Memory Corruption

Title source: rule

Description

Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Guido Landi · perllocalwindows
https://www.exploit-db.com/exploits/6787

Scores

EPSS 0.2581
EPSS Percentile 96.3%

Details

CWE
CWE-119
Status published
Products (50)
bittorrent/bittorrent 3.9.1
bittorrent/bittorrent 4.0.0
bittorrent/bittorrent 4.0.1
bittorrent/bittorrent 4.0.2
bittorrent/bittorrent 4.0.3
bittorrent/bittorrent 4.0.4
bittorrent/bittorrent 4.1.0
bittorrent/bittorrent 4.1.1
bittorrent/bittorrent 4.1.2
bittorrent/bittorrent 4.1.3
... and 40 more
Published Oct 03, 2008
Tracked Since Feb 18, 2026