CVE-2015-5685: Input Validation
Published Aug 13, 2015
·Updated
The lazybdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."
Affected Software
1 affected component
BitTorrent bootstrap-dht
Event History
Aug 13, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5685?
CVE-2015-5685 has a critical severity rating due to its potential for remote code execution.
2
How can I fix CVE-2015-5685?
To fix CVE-2015-5685, upgrade to the latest version of BitTorrent bootstrap-dht that includes the patch for this vulnerability.
3
What type of attacks can exploit CVE-2015-5685?
CVE-2015-5685 can be exploited by remote attackers sending crafted packets to execute arbitrary code.
4
Which software is affected by CVE-2015-5685?
CVE-2015-5685 affects the BitTorrent DHT bootstrap server, specifically bootstrap-dht without proper indexing protections.
5
What could happen if CVE-2015-5685 is exploited?
If exploited, CVE-2015-5685 could allow attackers to take control of the system and execute arbitrary commands.