CVE-2019-25586
MEDIUM
6,9
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
MEDIUM
6,2
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
Description
AI Translation Available
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the URL field. Attackers can paste a buffer of 5000 characters into the 'From URL' field during torrent addition to trigger an application crash.
466
Return of Pointer Value Outside of Expected Range
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Potential Impacts:
Read Memory
Modify Memory
Applicable Platforms
Languages:
C, C++, Memory-Unsafe
http://download.deluge-torrent.org/windows/deluge-1.3.15-win32-py2.7.exe
https://dev.deluge-torrent.org/
https://www.exploit-db.com/exploits/46883
https://www.vulncheck.com/advisories/deluge-denial-of-service-via-url-field