CVE-2008-4434

uTorrent < 1.7.7 and BitTorrent < 6.0.3 - Stack-Based Buffer Overflow via .torrent Created By Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4434. PoCs published by Guido Landi.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in BitTorrent 6.0.3 by crafting a malicious .torrent file. It uses a combination of Unicode-friendly shellcode, an egghunter, and a Venetian decoder to achieve remote code execution (RCE) by launching calc.exe.

Description

Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Guido Landi · perllocalwindows
https://www.exploit-db.com/exploits/6787

This exploit targets a stack buffer overflow in BitTorrent 6.0.3 by crafting a malicious .torrent file. It uses a combination of Unicode-friendly shellcode, an egghunter, and a Venetian decoder to achieve remote code execution (RCE) by launching calc.exe.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: BitTorrent 6.0.3
No auth needed
Prerequisites: Victim must open the malicious .torrent file in BitTorrent 6.0.3
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1020664
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31441
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2341
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2340
Various Sources x_refsource_confirm
http://forum.utorrent.com/viewtopic.php?id=44003
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31445
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30653
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44404
Mailing List mailing-list x_refsource_mlist
http://seclists.org/dailydave/2008/q3/0155.html

Scores

EPSS 0.1101
EPSS Percentile 95.3%

Details

CWE
CWE-119
Status published
Products (50)
bittorrent/bittorrent 3.9.1
bittorrent/bittorrent 4.0.0
bittorrent/bittorrent 4.0.1
bittorrent/bittorrent 4.0.2
bittorrent/bittorrent 4.0.3
bittorrent/bittorrent 4.0.4
bittorrent/bittorrent 4.1.0
bittorrent/bittorrent 4.1.1
bittorrent/bittorrent 4.1.2
bittorrent/bittorrent 4.1.3
... and 40 more
Published Oct 03, 2008
Tracked Since Feb 18, 2026