Date: Thu, 15 Feb 2007 20:43:34 -0600 (CST)
From: Gadi Evron <ge@linuxbox.org.>
To: [email protected]Subject: utorrent issue?
Message-ID: <Pine.LNX.4.21.0702152023040.4861-100000@linuxbox.org.>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-1.7.5 (linuxbox.org [127.0.0.1]); Thu, 15 Feb 2007 20:43:37 -0600 (CST)
X-Virus-Scanned: antivirus-gw at tyumen.ru
Hi, this did not hit bugtraq yet for some reason and it is serious. In AV
circles we are all worried about the abuse potential for this in malware.
uTorrent 1.6 build 474 (announce) Key Remote Heap Overflow Exploit
http://milw0rm.com/exploits/3296
Further Burak CIFTER wrote on this concern, comparing the utorrent
vulnerability to the SunOS one and how our security perceptions change:
http://blogs.securiteam.com/index.php/archives/825