EDonkey 2000 URI Handler Buffer Overflow Vulnerability
BID:4951
Info
EDonkey 2000 URI Handler Buffer Overflow Vulnerability
| Bugtraq ID: | 4951 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2002 12:00AM |
| Updated: | Jun 06 2002 12:00AM |
| Credit: | Credited to "Shane Hird" <[email protected]>. |
| Vulnerable: |
eDonkey 2000 Client 35.16.60 Windows eDonkey 2000 Client 35.16.59 Windows |
| Not Vulnerable: |
eDonkey 2000 Client 35.16.61 Windows eDonkey 2000 Client 16.16.59 Linux eDonkey 2000 Client 15.16.58 Mac OS X |
Discussion
EDonkey 2000 URI Handler Buffer Overflow Vulnerability
The eDonkey 2000 Windows client includes a handler for a custom URI, ed2k://. This URI handler allows for files to be retrieved from the network using MSIE or other tools which support it. It has been reported that the handler for eDonkey 2000 is vulnerable to a buffer overflow condition when parsing maliciously constructed URIs. This may be exploited to crash the user's browser or execute arbitrary code on the victim client.
The eDonkey 2000 Windows client includes a handler for a custom URI, ed2k://. This URI handler allows for files to be retrieved from the network using MSIE or other tools which support it. It has been reported that the handler for eDonkey 2000 is vulnerable to a buffer overflow condition when parsing maliciously constructed URIs. This may be exploited to crash the user's browser or execute arbitrary code on the victim client.
Exploit / POC
EDonkey 2000 URI Handler Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EDonkey 2000 URI Handler Buffer Overflow Vulnerability
Solution:
The vendor is aware of this vulnerability and has provided a new version.
eDonkey 2000 Client 35.16.59 Windows
eDonkey 2000 Client 35.16.60 Windows
Solution:
The vendor is aware of this vulnerability and has provided a new version.
eDonkey 2000 Client 35.16.59 Windows
-
eDonkey 2000 eDonkey61.exe
http://www.edonkey2000.com/files/eDonkey61.exe
eDonkey 2000 Client 35.16.60 Windows
-
eDonkey 2000 eDonkey61.exe
http://www.edonkey2000.com/files/eDonkey61.exe