------------------------------------ Product Description from the vendor:
BNBT was written by Trevor Hogan. BNBT is a complete port of the original Python BitTorrent tracker to C++ for speed and efficiency. BNBT also offers many additional features beyond the original Python BitTorrent tracker, plus it's easy to use and customizable. BNBT is covered under the GNU Lesser General Public License (LGPL).
-------- Details:
A specifically crafted HTTP GET request which contains 'Authorization: Basic A==' will cause the BNBT server to crash. It may be possible to execute arbitrary code. Previous versions are also affected by this vulnerability. The bug is located in util.cpp in the Util_DecodeHTTPAuth function.
-------- Exploit:
Attached to this advisory is very basic PoC code which only causes the BNBT server to crash.