Deluge 1.3.15 zawiera lukę denial of service, która pozwala lokalnym atakującym spowodować awarię aplikacji przez dostarczenie zbyt długiego ciągu znaków w polu Webseeds. Atakujący mogą wkleić bufor o rozmiarze 5000 bajtów w polu Webseeds podczas tworzenia torrenta, aby spowodować awarię aplikacji.
▸ Pokaż oryginał (EN)
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field during torrent creation to trigger an application crash.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDeluge Torrent Deluge
APPDeluge-Torrent1.3.15
Powiązane podatności
Path Traversal w komponencie WebUI Deluge — nieautoryzowany dostęp do plików
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a...
Deluge 1.3.15 zawiera podatność denial of service, która pozwala lokalnym atakującym na zawieszenie aplikacji ...
The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not ...