CVE-2009-5134

uTorrent 1.8.3 - Buffer Overflow via Large String in Create Torrent Dialog

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-5134. PoCs published by Dr_IDE.

AI-analyzed exploit summary This exploit is a buffer overflow PoC for uTorrent <= 1.8.3 (Build 15772). It generates a large string of 'A' characters (9000 bytes) and writes it to a file, which when pasted into the 'Source' field during torrent creation, triggers the overflow.

Description

Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a text file containing a large string. NOTE: some of these details are obtained from third party information.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Dr_IDE · pythondoswindows
https://www.exploit-db.com/exploits/9539

This exploit is a buffer overflow PoC for uTorrent <= 1.8.3 (Build 15772). It generates a large string of 'A' characters (9000 bytes) and writes it to a file, which when pasted into the 'Source' field during torrent creation, triggers the overflow.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: uTorrent <= 1.8.3 (Build 15772)
No auth needed
Prerequisites: uTorrent <= 1.8.3 (Build 15772) installed · User interaction to paste the string into the 'Source' field
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources x_refsource_confirm
http://forum.utorrent.com/viewtopic.php?id=58768
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52907
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9539

Scores

EPSS 0.0771
EPSS Percentile 93.8%

Details

CWE
CWE-119
Status published
Products (1)
utorrent/utorrent 1.8.3
Published Jan 18, 2013
Tracked Since Feb 18, 2026