Vulnerability Description
The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing."
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bittorrent | Bootstrap-Dht | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/70812
- http://www.zerodayinitiative.com/advisories/ZDI-14-370/
- https://github.com/bittorrent/bootstrap-dht/commit/bbc0b7191e3f48461ca6e5b1b34bdExploit
- http://www.securityfocus.com/bid/70812
- http://www.zerodayinitiative.com/advisories/ZDI-14-370/
- https://github.com/bittorrent/bootstrap-dht/commit/bbc0b7191e3f48461ca6e5b1b34bdExploit
FAQ
What is CVE-2014-8509?
CVE-2014-8509 is a vulnerability with a CVSS score of 7.5 (HIGH). The lazy_bdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper...
How severe is CVE-2014-8509?
CVE-2014-8509 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-8509?
Check the references section above for vendor advisories and patch information. Affected products include: Bittorrent Bootstrap-Dht.