The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libtorrent-rasterbar | Mar 31, 2017 | Jun 11, 2016 |
| Freebsd | — | Upgrade libtorrent-rasterbar | Dec 10, 2025 | Jun 30, 2016 |
| Suse | — | Upgrade python-libtorrent-rasterbarUpgrade python-libtorrent-rasterbar-debuginfoUpgrade libtorrent-rasterbar7Upgrade libtorrent-rasterbar-docUpgrade libtorrent-rasterbar7-debuginfoUpgrade libtorrent-rasterbar-debugsourceUpgrade libtorrent-rasterbar8Upgrade libtorrent-rasterbar-develUpgrade libtorrent-rasterbar8-debuginfo | Jun 21, 2016 | Jun 20, 2016 |
| Ubuntu | — | Upgrade python3-libtorrent (Ubuntu Pro)Upgrade python-libtorrent (Ubuntu Pro)Upgrade libtorrent-rasterbar7 (Ubuntu Pro)Upgrade libtorrent-rasterbar8 (Ubuntu Pro) | Mar 22, 2023 | Jun 30, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub