← back
CVE-2019-25585

Deluge 1.3.15 Denial of Service via Webseeds Field

CVSS 6.9 MEDIUMEPSS 0.2%CWE-1260
In short

Deluge 1.3.15 crashes when a user pastes an extremely long text (5000+ bytes) into the Webseeds field while creating a torrent. A local attacker can abuse this to crash the application and disrupt its availability.

Technical detail

A local denial of service vulnerability exists in Deluge 1.3.15's torrent creation functionality where the Webseeds input field lacks proper length validation. An attacker with local access can supply a buffer exceeding 5000 bytes to trigger an unhandled exception and application crash, resulting in unavailability of the service.

Summary generated and translated by AI from the official description.
Deluge 1.3.15 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the Webseeds field. Attackers can paste a buffer of 5000 bytes into the Webseeds field during torrent creation to trigger an application crash.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
Dev · Deluge

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →