CVE-2016-7164Improper Input Validation in Libtorrent-rasterbar

Severity
7.5HIGHNVD
EPSS
0.5%
top 35.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 7
Latest updateMay 17

Description

The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via a crafted GZIP response.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

debiandebian/libtorrent-rasterbar< libtorrent-rasterbar 1.1.1-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rw6x-mqq5-jg2g: The construct function in puff2022-05-17
OSV
CVE-2016-7164: The construct function in puff2017-02-07

📋Vendor Advisories

1
Debian
CVE-2016-7164: libtorrent-rasterbar - The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent tra...2016

💬Community

3
Bugzilla
CVE-2016-7164 libtorrent: Segmentation fault caused by malformed GZIP encoded response2016-09-08
Bugzilla
CVE-2016-7164 libtorrent: Segmentation fault caused by malformed GZIP encoded response [epel-all]2016-09-08
Bugzilla
CVE-2016-7164 libtorrent: Segmentation fault caused by malformed GZIP encoded response [fedora-all]2016-09-08