TorrentFreak

The place where breaking news, BitTorrent and copyright collide

Critical Vulnerability Discovered in uTorrent

A vulnerability described as ‘critical’ has been discovered in versions of uTorrent and the official BitTorrent client. The ‘buffer overflow’ vulnerability can be exploited to compromise a user’s computer for the execution of arbitrary code. It is suggested that users should immediately update to uTorrent version 1.8 RC7 or higher. There is currently no fix for the official client.

utorrentSecunia has issued two urgent security alerts, one for uTorrent and the other for the mainline BitTorrent client. Both clients are being developed by BitTorrent Inc.

The vulnerability was found in uTorrent and can be maliciously exploited to compromise a user’s computer, however, it also affects the mainline BitTorrent client, since it’s based on the uTorrent code.

According to Secunia, “the vulnerability is caused due to a boundary error in the processing of .torrent files. This can be exploited to cause a stack-based buffer overflow by tricking the user into opening a .torrent file containing an overly long ‘created by’ field”.

A successful execution of the exploit would allow the attacker to run arbitrary code on the victim’s machine.

The vulnerability exists in uTorrent version 1.7.7 (Build 8179) and may well affect earlier versions too, although this isn’t yet confirmed. The flaw is also present in the official BitTorrent client, versions 6.xx.

The solution for uTorrent users is to immediately upgrade to version 1.8. Currently there is no solution for those using the mainline client. However, an update will be available soon, TorrentFreak was told. For now, caution is advised when using unverified torrents.

Related Posts

Previous Post | Next Post

  • TorGuard

NewsBits

The latest news from around the web, not covered on the frontpage

  • TorrentFreak Censored by Orange’s Child Protection Filter

    The Internet is a scary place for kids, but luckily there’s censorship. In the UK mobile...

  • “How We Stopped SOPA”

    After the historic protests in January SOPA and PIPA were ‘shelved’. In a keynote speech at...

  • Supreme Court Refuses $675,000 File-Sharing Case

    The case of the RIAA vs. Joel Tenenbaum – aka the case that will not die...

  • MPAA: Piracy is NOT Theft After All

    For decades the entertainment industry used the word “theft” to refer to piracy. Most famous is...

  • Idiotic Copyright Comparisons in Canadian Parliament

    Politicians are always going the extra mile for their supporters, and nothing spells that out more...

MostDiscussed

Below are TorrentFreak's most discussed articles of the past month. Join the discussion if you like.

CopyQuote

Left Quote

“The Pirate Bay has been one of the most important movements in Sweden for freedom of speech, working against corruption and censorship.

Peter Sunde Left Quote

PopularArticles

A selection of some TorrentFreak's classics dug up from our archives.