CVE-2014-8509: Buffer Overflow
Published Oct 31, 2014
·Updated
The lazybdecode function in BitTorrent bootstrap-dht (aka Bootstrap) allows remote attackers to execute arbitrary code via a crafted packet, which triggers an out-of-bounds read, related to "Improper Indexing."
Affected Software
1 affected component
BitTorrent bootstrap-dht
Event History
Oct 31, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8509?
CVE-2014-8509 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2014-8509?
To fix CVE-2014-8509, update to the latest version of the BitTorrent Bootstrap-DHT software that addresses this vulnerability.
3
What types of attacks can CVE-2014-8509 facilitate?
CVE-2014-8509 can facilitate remote code execution attacks through a crafted packet targeting the lazy_bdecode function.
4
Which software is affected by CVE-2014-8509?
CVE-2014-8509 affects the BitTorrent bootstrap-dht component.
5
What causes the vulnerability in CVE-2014-8509?
CVE-2014-8509 is caused by improper indexing in the lazy_bdecode function leading to an out-of-bounds read.