CVE-2020-8437: Null Pointer Dereference
Published Mar 2, 2020
·Updated
The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.
Affected Software
1 affected component
BitTorrent uTorrent<=3.5.5
Event History
Mar 2, 2020
CVE Published
via MITRE·06:33 PM
Data Sourced
via MITRE·06:33 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8437?
CVE-2020-8437 is considered a moderate severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2020-8437?
To fix CVE-2020-8437, upgrade to a newer version of BitTorrent uTorrent that is not affected by this vulnerability.
3
What type of attack does CVE-2020-8437 allow?
CVE-2020-8437 allows a remote attacker to exploit a denial of service via misparsed nested bencoded dictionaries.
4
Which versions of uTorrent are affected by CVE-2020-8437?
CVE-2020-8437 affects BitTorrent uTorrent versions up to and including 3.5.5 (build 45505).
5
What is the impact of exploiting CVE-2020-8437?
Exploiting CVE-2020-8437 can lead to application crashes and make the service unavailable to users.