|
|
[ Message Precedent sur la mailing][ Message Suivant sur la mailing][ Precedent dans le fil][ Prochain dans le fil][ Index par Date][ Index par fil]
[SA30997] Download Accelerator Plus M3U File Buffer Overflow
Want a new job?
link://[click]
link://[click]
International Partner Manager - Project Sales in the IT-Security
Industry:
link://[click]
TITLE:
Download Accelerator Plus M3U File Buffer Overflow
SECUNIA ADVISORY ID:
SA30997
VERIFY ADVISORY:
link://[click]
CRITICAL:
Moderately critical
IMPACT:
System access
WHERE:
From remote
REVISION:
2.0 originally posted 2008-07-09
SOFTWARE:
Download Accelerator Plus 8.x
link://[click]
Download Accelerator Plus 7.x
link://[click]
DESCRIPTION:
Krystian Kloskowski has discovered a vulnerability in Download
Accelerator Plus, which can be exploited by malicious people to
compromise a user's system.
The vulnerability is caused due to a boundary error when verifying
URLs within a .m3u file. This can be exploited to cause a stack-based
buffer overflow when a user is tricked into verifying an overly long
URL in a specially crafted .m3u file.
Successful exploitation allows execution of arbitrary code.
The vulnerability is confirmed in version 8.6.6.3 (DAP.exe) and
7.0.1.3 (DAP.exe). Other versions may also be affected.
SOLUTION:
Do not import .m3u files from untrusted sources.
PROVIDED AND/OR DISCOVERED BY:
Krystian Kloskowski (h07)
CHANGELOG:
2008-07-09: Added version 7.x to list of affected products.
ORIGINAL ADVISORY:
link://[click]
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
link://[click]
Definitions: (Criticality, Where etc.)
link://[click]
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
Archives de la liste de diffusion Secunia
Archives de la liste de diffusion Full Disclosure
| Mini-Tagwall des articles publiés sur SecuObs : | | | | sécurité, exploit, windows, attaque, outil, microsoft, réseau, audit, metasploit, vulnérabilité, système, virus, internet, usbsploit, données, source, linux, protocol, présentation, scanne, réseaux, scanner, bluetooth, conférence, reverse, shell, meterpreter, vista, rootkit, détection, mobile, security, malicieux, engineering, téléphone, paquet, trames, https, noyau, utilisant, intel, wishmaster, google, sysun, libre |
| Mini-Tagwall de l'annuaire video : | | | | curit, security, biomet, metasploit, biometric, cking, password, windows, botnet, defcon, tutorial, crypt, xploit, exploit, lockpicking, linux, attack, wireshark, vmware, rootkit, conference, network, shmoocon, backtrack, virus, conficker, elcom, etter, elcomsoft, server, meterpreter, openvpn, ettercap, openbs, iphone, shell, openbsd, iptables, securitytube, deepsec, source, office, systm, openssh, radio |
| Mini-Tagwall des articles de la revue de presse : | | | | security, microsoft, windows, hacker, attack, network, vulnerability, google, exploit, malware, internet, remote, iphone, server, inject, patch, apple, twitter, mobile, virus, ebook, facebook, vulnérabilité, crypt, source, linux, password, intel, research, virtual, phish, access, tutorial, trojan, social, privacy, firefox, adobe, overflow, office, cisco, conficker, botnet, pirate, sécurité |
| Mini-Tagwall des Tweets de la revue Twitter : | | | | security, linux, botnet, attack, metasploit, cisco, defcon, phish, exploit, google, inject, server, firewall, network, twitter, vmware, windows, microsoft, compliance, vulnerability, python, engineering, source, kernel, crypt, social, overflow, nessus, crack, hacker, virus, iphone, patch, virtual, javascript, malware, conficker, pentest, research, email, password, adobe, apache, proxy, backtrack |
|
|
|
|
|