RSS Archive Contact Us Advertise

IT Management Begins With Security
SecurityProNews > Insider Reports > Insider > BitTorrent Clients Suffer Overflow Flaw
Search:
[ insider_reports_insider ]

BitTorrent Clients Suffer Overflow Flaw



David Utter
Staff Writer
2008-08-14

SecurityProNews: Insider Reports Insider Reports RSS Feed


Software clients from BitTorrent and uTorrent contain critical vulnerabilities that could permit remote code execution.

BitTorrent Clients Suffer Overflow Flaw
BitTorrent Clients Suffer Overflow Flaw

The BitTorrent protocol permit fast sharing of files through a peer to peer process. Since people use it to move copyrighted material as well as works not restricted that way, the usage of P2P continues to be controversial.

Security matters about the protocol are anything but controversial. When there is a flaw, someone will try to exploit it, and the popular appeal of BitTorrent makes it likely such an attempt could affect a lot of people.

That makes the report out of security issue tracker Secunia, which said a stack based buffer overflow could be triggered by opening a .torrent file with an overly long "created by" field. The use of uTorrent's code in the BitTorrent client makes it vulnerable in similar fashion.

Users of uTorrent can upgrade to the 1.8 RC7 version to eliminate the problem. The BitTorrent client has no solution or workaround available other than to avoid opening untrusted .torrent files.

It's not news, it's MSNBC spam: If MSNBC felt left out while all of that fake CNN spam hit inboxes everywhere, they can stop worrying. Junk messages leading people to a phony CNN video codec, actually a disguised Trojan file, now have a copycat MSNBC version in circulation.

PandaLabs said on their blog they witnessed MSNBC Breaking News spam leading people to the same fake CNN file. The security vendor said they expect to see more copycat spam in other variations hit the Internet in coming days.



About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More insider_reports_insider Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds