Nulvas Posted April 7, 2015 Report Share Posted April 7, 2015 The related report:http://www.securityweek.com/command-injection-vulnerability-found-bittorrent-sync “The vulnerability relates to how BitTorrent Sync handles URLs with the btsync protocol. By navigating the user to a specially formed link starting with btsync:, an attacker can inject arbitrary command line parameters that will be passed to BTSync.exe. An attacker can leverage this vulnerability to execute code under the context of the current user,” ZDI wrote in its advisory. Quote Link to comment Share on other sites More sharing options...
RomanZ Posted April 7, 2015 Report Share Posted April 7, 2015 @NulvasI suggest you mean 1.4.111 as 1.4.11 was never released. 1.4.111 is not vulnerable to CVE-2015-2846 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.