SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-5134

Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly…

MEDIUM 6.8EPSS 7.71%

Does this matter?

Lower severity and a low EPSS score (7.71%). Track it; it rarely justifies an emergency change on its own.

Description

Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a text file containing a large string. NOTE: some of these details are obtained from third party information.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
7.71% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
utorrent/utorrent
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.