This forum has been archived. All content is frozen. Please use KDE Discuss instead.

possible security issue

Tags: None
(comma "," separated)
Valkyria
Registered Member
Posts
1
Karma
0

possible security issue

Fri Dec 08, 2006 1:17 pm
I don't know if this is really a security issue, or if someone mentioned it before, but I thought it wouldn't hurt to mention it here.
I was just playing with nmap, testing my system with the possible scans to learn about what each type of scan does, while I was waiting for a torrent to finish downloading. And when I do an UDP scan, guess what? Ktorrent (v 2.1beta1) crashes. It's repeatable, from what I see.
From what I understand, nmap sends an empty UPD header to the ports it's scanning.
So... a way to remotely crash ktorrent... Can it cause any other problems?
George
Moderator
Posts
5421
Karma
1

Sat Dec 09, 2006 9:37 am
Probably a bug in either the UPnP plugin or the DHT implementation, I will check it out.

Don't know if this would be a security issue, but it is probably easily fixed.
George
Moderator
Posts
5421
Karma
1

Sat Dec 09, 2006 10:12 am
What nmap command did you use to scan ?
George
Moderator
Posts
5421
Karma
1

Sat Dec 09, 2006 12:29 pm
Nevermind, I was not able to reproduce the crash with the latest code from SVN, but I did find a bug with the KDE socket classes, which do not handle empty UDP packets properly.

I have now added some safety checks for empty UDP packets, which will prevent a crash and also prevent the KDE socket classes from behaving badly.


Bookmarks



Who is online

Registered users: Bing [Bot], Google [Bot], q.ignora, watchstar