Update libtorrent-rasterbar to latest 1.x release

Bug #1485365 reported by Nick B.
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
libtorrent-rasterbar (Debian)
Fix Released
Unknown
libtorrent-rasterbar (Ubuntu)
In Progress
Wishlist
Andrew Starr-Bochicchio

Bug Description

Ubuntu has an extremely old version of libtorrent-rasterbar. 0.16.8. The latest upstream release is 1.0.6. Some programs like qbittorrent require the 1.x version for certain features and builds against 1.x by default. The minimum version was recently bumped to 0.16.9 which makes it impossible to build qbittorrent now. Could someone please get the 1.x release into Ubuntu?

tags: added: upgrade-software-version
Changed in libtorrent-rasterbar (Ubuntu):
status: New → In Progress
importance: Undecided → Wishlist
assignee: nobody → Andrew Starr-Bochicchio (andrewsomething)
Changed in libtorrent-rasterbar (Debian):
status: Unknown → Fix Released
Revision history for this message
Xavier Guillot (valeryan-24) wrote :

Hi, regarding the vulnerability recently patched against DRDoS Vulnerability in the BitTorrent ecosystem, and as Debian package has already been updated, it is urgent now for security that Ubuntu also makes version 1.0.6 with the fix available for all distributions, as clients such Deluge and qBitTorrent depend from libtorrent-rasterbar.

Here are data on this bug:
http://blog.bittorrent.com/2015/08/27/mitigating-drdos-vulnerability-in-the-bittorrent-ecosystem/
https://github.com/arvidn/libtorrent/commit/677e64275405a3a2fd9017c8b4c51f9cc5e0a2e1
http://www.researchgate.net/publication/280878634_P2P_File-Sharing_in_Hell_Exploiting_BitTorrent_Vulnerabilities_to_Launch_Distributed_Reflective_DoS_Attacks

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.