Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.800349
Categoría:Buffer overflow
Título:Multiple Buffer Overflow Vulnerabilities in Free Download Manager
Resumen:This host has installed Free Download Manager and is prone to; multiple buffer overflow vulnerability.
Descripción:Summary:
This host has installed Free Download Manager and is prone to
multiple buffer overflow vulnerability.

Vulnerability Insight:
Multiple buffer overflow errors due to:

- a long file name within a torrent file.

- a long tracker URL in a torrent file.

- a long comment in a torrent file.

- a long Authorization header in an HTTP request.

Vulnerability Impact:
Successful exploitation could allow remote attackers to execute arbitrary
code and can cause denial-of-service in the affected application.

Affected Software/OS:
Free Download Manager version prior to 3.0 build 848 on Windows.

Solution:
Upgrade to version 3.0 build 848.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2009-0183
BugTraq ID: 33554
http://www.securityfocus.com/bid/33554
Bugtraq: 20090202 Secunia Research: Free Download Manager Remote Control Server Buffer Overflow (Google Search)
http://www.securityfocus.com/archive/1/500604/100/0/threaded
https://www.exploit-db.com/exploits/7986
http://secunia.com/secunia_research/2009-3/
http://osvdb.org/51745
http://secunia.com/advisories/33524
http://www.vupen.com/english/advisories/2009/0302
Common Vulnerability Exposure (CVE) ID: CVE-2009-0184
BugTraq ID: 33555
http://www.securityfocus.com/bid/33555
Bugtraq: 20090202 Secunia Research: Free Download Manager Torrent Parsing Buffer Overflows (Google Search)
http://www.securityfocus.com/archive/1/500605/100/0/threaded
http://secunia.com/secunia_research/2009-5/
CopyrightCopyright (C) 2009 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.