Описание
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libtorrent-rasterbar | fixed | 1.1.1-1 | package | |
| libtorrent-rasterbar | no-dsa | jessie | package | |
| libtorrent-rasterbar | not-affected | wheezy | package |
Примечания
https://github.com/arvidn/libtorrent/issues/1021
https://github.com/arvidn/libtorrent/pull/1022
https://github.com/arvidn/libtorrent/commit/debf3c6e3688aab8394fe5c47737625faffe6f9e
Fixed upstream in 1.1.1.
Связанные уязвимости
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.
The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.