CVE-2004-2433
Summary
| CVE | CVE-2004-2433 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Altnet | Altnet Download Manager | 4.0.0.4 | All | All | All |
| Application | Altnet | Altnet Download Manager | All | All | All | All |
| Application | Grokster | Grokster | 1.3 | All | All | All |
| Application | Grokster | Grokster | 1.3.3 | All | All | All |
| Application | Grokster | Grokster | 2.6 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 1.3 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 1.3.1 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 1.3.2 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 1.6.1 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 2.0 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 2.0.2 | All | All | All |
| Application | Kazaa | Kazaa Media Desktop | 2.6.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Altnet ADM ActiveX Control Remote Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch |
| Secunia - Advisories - Grokster Altnet Download Manager Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.osvdb.org/9549 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Secunia - Advisories - Altnet Download Manager Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Altnet Download Manager Buffer Overflow in bstrFilepath Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.