Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
BID:25903
Info
Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
| Bugtraq ID: | 25903 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-5217 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2007 12:00AM |
| Updated: | Nov 04 2008 07:15PM |
| Credit: | Parvez Anwar is credited with the discovery of this issue. |
| Vulnerable: |
KaZaA KaZaA Media Desktop 3.0 KaZaA KaZaA Media Desktop 2.6.4 KaZaA KaZaA Media Desktop 2.0.2 KaZaA KaZaA Media Desktop 2.0 KaZaA KaZaA Media Desktop 1.6.1 KaZaA KaZaA Media Desktop 1.3.2 KaZaA KaZaA Media Desktop 1.3.1 KaZaA KaZaA Media Desktop 1.3 Grokster Grokster 2.6 Grokster Grokster 1.3.3 Grokster Grokster 1.3 Altnet Altnet Download Manager 4.0 |
| Not Vulnerable: | |
Discussion
Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
Altnet Download Manager ADM4 ActiveX control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to cause a denial-of-service condition or to execute arbitrary code.
This issue affects Altnet Download Manager 4.0; other versions may also be affected. KaZaA and Grokster are considered vulnerable as well.
Altnet Download Manager ADM4 ActiveX control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to cause a denial-of-service condition or to execute arbitrary code.
This issue affects Altnet Download Manager 4.0; other versions may also be affected. KaZaA and Grokster are considered vulnerable as well.
Exploit / POC
Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available as a module for the Metasploit Framework:
To exploit this issue, an attacker must entice an unsuspecting user to access a malicious webpage.
The following exploit code is available as a module for the Metasploit Framework:
Solution / Fix
Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Altnet Download Manager ADM4 ActiveX Buffer Overflow Vulnerability
References:
References:
- Altnet Download Manager (Altnet)
- Homepage (Altnet)
- Microsoft Knowledge Base Article 240797 (Microsoft)