Altnet ADM ActiveX Control远程缓冲区溢出漏洞

漏洞信息详情

Altnet ADM ActiveX Control远程缓冲区溢出漏洞

漏洞简介

Altnet Download Manager 4.0.0.4及其之前版本中ADM ActiveX控件的IsValidFile函数存在缓冲区溢出漏洞,如在Kazaa Media Desktop 1.3到2.6.4版本中,和Grokkster 1.3到2.6版本中使用时,远程攻击者可以借助一个超长bstrFilepath参数执行任意代码。

漏洞公告

It is reported that the vendor has released an upgrade to address this issue.
Altnet ADM

参考网址

来源: BID
名称: 11101
链接:http://www.securityfocus.com/bid/11101

来源: SECUNIA
名称: 12446
链接:http://secunia.com/advisories/12446

来源: XF
名称: adm-bstrfilepath-bo(17221)
链接:http://xforce.iss.net/xforce/xfdb/17221

来源: OSVDB
名称: 9549
链接:http://www.osvdb.org/9549

来源: SECTRACK
名称: 1011155
链接:http://securitytracker.com/id?1011155

来源: SECUNIA
名称: 12456
链接:http://secunia.com/advisories/12456

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享