CVE-2015-2846: Command Injection
Published Apr 13, 2015
·Updated
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
Affected Software
1 affected component
BitTorrent Sync
Event History
Apr 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2846?
CVE-2015-2846 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2015-2846?
To fix CVE-2015-2846, update BitTorrent Sync to the latest version provided by the vendor that has addressed this vulnerability.
3
What software is affected by CVE-2015-2846?
CVE-2015-2846 affects BitTorrent Sync versions prior to the security update.
4
What type of attack can be executed using CVE-2015-2846?
CVE-2015-2846 allows remote attackers to execute arbitrary commands on affected systems.
5
Is there a way to mitigate CVE-2015-2846 if I cannot update?
If you cannot update, consider restricting access to BitTorrent Sync and monitoring for any suspicious command execution.