Internet Download Manager Buffer Overflow Vulnerability
BID:14159
Info
Internet Download Manager Buffer Overflow Vulnerability
| Bugtraq ID: | 14159 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | c0d3r "Kaveh Razavi" <[email protected]> disclosed this vulnerability, but bigboss is credited with its discovery. |
| Vulnerable: |
Internet Download Manager Corp. Internet Download Manager 4.0 5 Internet Download Manager Corp. Internet Download Manager 4.0 4 Internet Download Manager Corp. Internet Download Manager 4.0 3 Internet Download Manager Corp. Internet Download Manager 4.0 2 Internet Download Manager Corp. Internet Download Manager 4.0 1 Internet Download Manager Corp. Internet Download Manager 4.00 Internet Download Manager Corp. Internet Download Manager 3.x Internet Download Manager Corp. Internet Download Manager 2.x |
| Not Vulnerable: | |
Discussion
Internet Download Manager Buffer Overflow Vulnerability
Internet Download Manager is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check input data prior to copying it into a fixed size memory buffer.
This vulnerability allows attackers to overflow a memory buffer, overwriting adjacent memory regions. This allows attackers to influence the normal flow of execution of the application, potentially leading to arbitrary machine code execution in the context of the user executing the vulnerable application.
Internet Download Manager version 4.05 and prior are reported to be vulnerable to this issue.
Internet Download Manager is susceptible to a buffer overflow vulnerability. This issue is due to a failure of the application to properly bounds check input data prior to copying it into a fixed size memory buffer.
This vulnerability allows attackers to overflow a memory buffer, overwriting adjacent memory regions. This allows attackers to influence the normal flow of execution of the application, potentially leading to arbitrary machine code execution in the context of the user executing the vulnerable application.
Internet Download Manager version 4.05 and prior are reported to be vulnerable to this issue.
Exploit / POC
Internet Download Manager Buffer Overflow Vulnerability
A proof of concept exploit is provided:
A proof of concept exploit is provided:
Solution / Fix
Internet Download Manager Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Internet Download Manager Buffer Overflow Vulnerability
References:
References:
- Internet Download Manager Homepage (Internet Download Manager Corp.)