uTorrent 1.7.7 Stable Fixes Security Issues

Written by Ernesto on January 27, 2008 

The uTorrent development team just released 1.7.7 stable. The new version is the latest 1.7 release, and fixes the vulnerability that allowed attackers to remotely crash the BitTorrent client.

utorrent logoTwo weeks ago we reported that several versions of the popular BitTorrent client uTorrent were vulnerable to a remote DoS attack.

The vulnerability was discovered by Luigi Auriemma, a Milan-based security expert. He claimed that various BitTorrent clients were subject to this security flaw, based on the way they handle user-supplied data. The vulnerability was not critical, but it did allow attackers to remotely crash the application.

In a response, the uTorrent team stated that several of the older uTorrent releases were also affected. Luckily, they quickly released a new build - uTorrent 1.7.6 (build 7859), in which they fixed the issue, and the latest stable release is now safe as well.

The latest stable release of uTorrent adresses both the remote crash bug in WebUI and the (potential) remote crash bug with extension protocol. In the release notes we read: “1.7.7 is released to fix some potential security exploits. Barring any other security issues before the release of 1.8, this will be the last 1.7.x release.”

uTorrent is by far the most used BitTorrent client, and is installed on 5% of all Windows PCs worldwide, according to recent reports. The BitTorrent mainline client - also developed by BitTorrent Inc. - comes in second place, before Azureus and BitComet.

The latest stable release can be downloaded over here, upgrading is of course recommended.

Previously: The Pirate Bay Now Tracks 1 Million Torrents, 10 Million Peers

Next: Most Popular DVDrips on BitTorrent (wk4)

42 Responses (Add yours or TrackBack)

Pages: [1] 2 » Show All

1 Jan 27, 2008 at 13:13 by jo

utorrent 1.7.6 is fucked up. Can’t get my torrents to work and a roll back doesn’t do anything either. Been working on this for the last couple of days and now in the process of installing my windows again

2 Jan 27, 2008 at 13:22 by JoeRodge

hes blown

3 Jan 27, 2008 at 13:53 by Oliver

To all you 1.7.X’s out there, try the new 1.8 Alpha instead.

I’s much more solid =)

µTorrent 1.8 Build 8188 Alpha

http://forum.utorrent.com/viewtopic.php?id=31998

4 Jan 27, 2008 at 14:28 by system

It’s no suprise the alpha is more stable than the “stable”.
uT has a bad habbit of calling everything they release in the 1.7.x branch a stable, despite having to regularly release 2 or 3 versions in the same week.

5 Jan 27, 2008 at 14:46 by smartass

I wonder if the Private trackers already support them. I won’t upgrade until my trackers say it’s A.OK

6 Jan 27, 2008 at 14:58 by The P!nk Pr!nce

I converted to Azureus about a week ago from uTozz don’t really see any reason for changing back now!

7 Jan 27, 2008 at 15:24 by uTorrent Uber Alles

[quote comment="273464"]I converted to Azureus about a week ago from uTozz don’t really see any reason for changing back now![/quote]

The fact that uTorrent is better isn’t a good enough reason?

8 Jan 27, 2008 at 16:03 by Anonymous

[quote comment="273473"][quote comment="273464"]I converted to Azureus about a week ago from uTozz don’t really see any reason for changing back now![/quote]

The fact that uTorrent is better isn’t a good enough reason?[/quote]
Whatever…

9 Jan 27, 2008 at 16:08 by Ali G

is you on crack or somethin’?

10 Jan 27, 2008 at 16:09 by Blanchimont

Still using uTorrent 1610 and never had problems…Should I be worried?

11 Jan 27, 2008 at 16:28 by Dutchy

No, you don’t have to worry. 1.6.1 does not have this issue, however all other versions between there and 1.7.6 have the security issue. I have upgraded to 1.7.7 and it works fine, hopefully this is the last time that I have to think about this for a while.

12 Jan 27, 2008 at 16:34 by Licking my Bitch

I have and i use version 1.6.1.490 for long time. Works perfect, is stable, never had problems. It was time the real guy was programmer for utorrent. Now utorrent got fucked up by other boys have no skills about good programming!

13 Jan 27, 2008 at 16:39 by George W. Bush

[quote comment="273510"]I have and i use version 1.6.1.490 for long time. Works perfect, is stable, never had problems. It was time the real guy was programmer for utorrent. Now utorrent got fucked up by other boys have no skills about good programming![/quote]

WA GWAN?

DIS BWOY BE RA-III-GHT!

BOOYAKASHAH!

(Is it cos I is black?)

14 Jan 27, 2008 at 16:49 by Spanky69

From a privet site that is on the ball, pretty strict regarding what clients they will allow.

There is an EXPLOIT in All versions of uTorrent below version 1.7.7 (including uTorrent 1.6 but not 1.6.1) that can allow an attacker to crash your client and possible code execution on your machine. In 1.7.6 it affected the webUI part.
Until further notice 1.6 and 1.6.1 are still allowed but version 1.7.5 and 1.7.6 is now banned. We do recommend you upgrade to uTorrent 1.7.7 if running uTorrent 1.7.5 or 1.7.6.

15 Jan 27, 2008 at 17:06 by Anonymous Cop

Well too bad Bitorrent isn’t open source anymore you dumbasses, :)) hahahahahaha die sharers die!

16 Jan 27, 2008 at 17:55 by Crandom

Use the 1.8 alpha. I’ve gone from around 1.8mb/s on 1.7.4 to 2.3mb/s on a 20mbit line with it!

17 Jan 27, 2008 at 17:55 by Crandom

[quote comment="273538"]Well too bad Bitorrent isn’t open source anymore you dumbasses, :)) hahahahahaha die sharers die![/quote]

Kindly fuck off.

18 Jan 27, 2008 at 19:44 by embedded torrent nodes

for seeding large amount of data or torrents, rtorrent looks best.
Its not windows compatible UI program but it can easy run it on your home router with attached storage or NAS. With GUI running on windows.

19 Jan 27, 2008 at 21:55 by private ftw

azureus <3

20 Jan 27, 2008 at 22:23 by jaycup

i never had any problems with any version of utorrent.

21 Jan 27, 2008 at 23:23 by Calvin

I upgraded as soon as soon it came out. In fact, i’m the lulz who sent this in. =P

22 Jan 28, 2008 at 00:04 by Kevin

Just have a question. If i use the 1.8 alpha on private trackers, and it’s banned, will my ass be banned too? I don’t want to take the risk.

23 Jan 28, 2008 at 01:07 by anonymous

[quote comment="273744"]Just have a question. If i use the 1.8 alpha on private trackers, and it’s banned, will my ass be banned too? I don’t want to take the risk.[/quote]

No, you just won’t be able to connect. Most private trackers allow the beta, though.

24 Jan 28, 2008 at 02:18 by heh

Ernesto likes it in the ass

25 Jan 28, 2008 at 06:25 by Dr.Arthur

[quote comment="273538"]Well too bad Bitorrent isn’t open source anymore you dumbasses, :)) hahahahahaha die sharers die![/quote]
It still is. It’s just no longer used by Bittorrent.com as a mainline client. If you want a badass Open Source client, get Deluge.

Pages: [1] 2 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.