Command Injection Vulnerability Found in BitTorrent Sync

Status
Not open for further replies.

Petrovic

Level 64
Thread author
Verified
Honorary Member
Top Poster
Well-known
Apr 25, 2013
5,357
20,489
6,278
Somewhere In nowhere
A serious security flaw in BitTorrent Sync can be exploited by a remote attacker to execute arbitrary code, according to an advisory published over the weekend by HP’s Zero Day Initiative (ZDI).

BitTorrent Sync is a peer-to-peer file synchronization application developed by San Francisco-based Internet technology company BitTorrent, Inc. Available for all the major mobile and desktop platforms, the tool allows users to sync files between local or remote devices. In August 2014, BitTorrent reported that the app had more than 10 million user installs, with a total of over 80 petabytes of data transferred.

Andrea Micalizzi, also known as “rgod,” has identified a btsyncprotocol command injection vulnerability (CVE-2015-2846) that can be exploited for remote code execution. The researcher reported his findings to BitTorrent in early November 2014 through ZDI.

Full Article
 
  • Like
Reactions: thepierrezou
Status
Not open for further replies.