UBUNTU-CVE-2015-5685

Source
https://ubuntu.com/security/CVE-2015-5685
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2015/UBUNTU-CVE-2015-5685.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2015-5685
Upstream
Published
2015-08-13T14:59:00Z
Modified
2025-09-08T16:43:26Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing."

References

Affected packages

Ubuntu:Pro:14.04:LTS / libtorrent-rasterbar

Package

Name
libtorrent-rasterbar
Purl
pkg:deb/ubuntu/libtorrent-rasterbar@0.16.13-1ubuntu2.1+esm1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.16.11-1ubuntu1
0.16.11-1ubuntu2
0.16.11-1ubuntu4
0.16.11-1ubuntu5
0.16.13-1ubuntu1
0.16.13-1ubuntu2
0.16.13-1ubuntu2.1
0.16.13-1ubuntu2.1+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "0.16.13-1ubuntu2.1+esm1",
            "binary_name": "libtorrent-rasterbar-dev"
        },
        {
            "binary_version": "0.16.13-1ubuntu2.1+esm1",
            "binary_name": "libtorrent-rasterbar7"
        },
        {
            "binary_version": "0.16.13-1ubuntu2.1+esm1",
            "binary_name": "python-libtorrent"
        },
        {
            "binary_version": "0.16.13-1ubuntu2.1+esm1",
            "binary_name": "python3-libtorrent"
        }
    ]
}