Infesting you with Virus News
 

Vulnerabilities

Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 torrent parsing... (PC1-2009-0387)

Overview

Vulnerability chart

Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
1 vulnerability found since 3 February, 2009.
The software is defined as an effective, simple-to-use and free download... more
1 files found: fdm.exe... more
Multiple buffer overflow vulnerabilities were found in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844.
Remote Access
Yes, patch
is available
Patch is easy
to implement

References to Advisories, Solutions, and Tools

Description:

By using multiple buffer overflow vulnerabilities in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844, remote attackers are enabled to execute arbitrary code in the three ways listed below:
(1) through a long file name within a torrent file;
(2) through a long tracker URL in a torrent file;
(3) through a long comment in a torrent file.

Impact:

This type of vulnerability gives administrator access. Also, it permits complete confidentiality, integrity, and availability violation. Moreover, it enables unauthorized revelation of information and interruption of service.

Solution:

We recommend users to upgrade to the latest version of the software product.

References:http://www.frsirt.com/english/advisories/2009/0302
http://www.securityfocus.com/bid/33555
http://www.securityfocus.com/archive/1/archive/1/500605/100/0/threaded
http://secunia.com/secunia_research/2009-5/
http://secunia.com/advisories/33524

Impact

CVSS Severity

CVSS Version 2 Metrics:

CVSS v2 Base Score:9.3 (HIGH)Access Vector:N/A
Impact Subscore: 10.0Access Complexity: Medium
Exploitability Subscore: 8.6Authentication: Not required to exploit
Impact Type:Provides administrator access, Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service

Say something interesting!

naveen 2009-09-01
i want to download internet download manager
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Latest Comments

March 12, 2010
I am not fake. more..
March 12, 2010
Very nasty thing it killed alot of files that were essential for windows to even run It turned... more..
March 12, 2010
sir i was interest to learn hacking more..
more comments..
rss
Home > Vulnerabilities > pc1-2009-0387