uTorrent patches application against DLL vulnerability

uTorrent is one of many applications that is affected by the vulnerability

The developers of the uTorrent file-sharing application have released an updated version that fixes a problem that could allow an attacker to load malicious code onto a user's computer.

The problem, known as DLL (dynamic link library) load hijacking, affects dozens of commonly used Windows applications. The flaw can allow an attacker to trick an application into downloading what it thinks is a DLL but actually is a malicious file. A DLL is a piece of code that can be used by more than one application.

The issue affects more than 40 applications including the Safari and Firefox browsers, many Microsoft and Adobe Systems applications and others including Skype and uTorrent.

UTorrent version 2.0.4 fixes the problem, although the company behind the application, BitTorrent, said that no attacks have been reported despite a working exploit.

"The new client disables loading of DLLs from the current working directory and prevents this exploit from functioning," according to the posting. "We take our users' security very seriously, and we sincerely apologize for any inconvenience."

The DLL problem isn't specific to the Windows OS, and Microsoft can't issue a patch that makes all of the applications safe. Application developers and companies need to develop their own specific patches.

UTorrent is a free BitTorrent client application that manages the downloading of content from the peer-to-peer system, which uses small information files called torrent to coordinate downloads.

Send news tips and comments to jeremy_kirk@idg.com

More about: Adobe, Adobe Systems, Microsoft, Skype
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the TechWorld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: bittorrent, exploits and vulnerabilities, malware, patches, security, uTorrent
Whitepapers
All whitepapers

Twitter Feed

  • rohan_p RT @Techworld_AU: Gear and gadgets at @CeBITAUS 2012, Sydney http://t.co/J1Sch1sX #cebit2012
  • Techworld_AU Gear and gadgets at @CeBITAUS 2012, Sydney http://t.co/J1Sch1sX #cebit2012
  • HamishBarwick CeBIT 2012: Will NBN speed up freight delivery times? http://t.co/gaZyjOlH #cw #cio #tw #CeBIT2012 #nbn
  • HamishBarwick CeBIT 2012: NAB calls for mobile app security overhaul http://t.co/3Z3ZPUPq #cw #cio #tw #CeBIT2012 #infosec
  • rohan_p RT @Techworld_AU: BigPond Games Arena, Games Shop hit by hackers http://t.co/OXNPeDfL #bigpond #infosec #security