CVE-2015-5474: Command Injection
Published Aug 13, 2015
·Updated
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
Affected Software
2 affected components
BitTorrent BitTorrent
uTorrent uTorrent
Event History
Aug 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5474?
CVE-2015-5474 is considered a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2015-5474?
To mitigate CVE-2015-5474, update to the latest versions of BitTorrent or uTorrent that address this vulnerability.
3
What types of attacks are possible with CVE-2015-5474?
CVE-2015-5474 allows remote attackers to inject command line parameters and execute arbitrary commands through crafted URLs.
4
Which applications are affected by CVE-2015-5474?
CVE-2015-5474 affects both BitTorrent and uTorrent applications.
5
Can CVE-2015-5474 be exploited via email links?
Yes, CVE-2015-5474 can be exploited using malicious links in emails or other messages that utilize the bittorrent or magnet protocols.