Debian Security Advisory 1817-1 – Michael Brooks discovered that ctorrent, a text-mode bittorrent client, does not verify the length of file paths in torrent files. An attacker can exploit this via a crafted torrent that contains a long file path to execute arbitrary code with the rights of the user opening the file.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/78529/dsa-1817-1.txt
Source: https://packetstormsecurity.com/files/78529/Debian-Linux-Security-Advisory-1817-1.html