vendor:
GetGo Download Manager
by:
devcoinfet
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: GetGo Download Manager
Affected Version From: 5.3.0.2712
Affected Version To: 5.3.0.2712
Patch Exists: YES
Related CWE: N/A
CPE: a:getgo_software:getgo_download_manager
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 8 64 bits
2018
Buffer overflow vulnerability in GetGo Download Manager proxy options 5.3.0.2712
A buffer overflow vulnerability exists in GetGo Download Manager proxy options 5.3.0.2712, where a maliciously crafted response from a proxy can trigger an overflow. The victim must have a proxy selected in order to be vulnerable. The attacker can set the proxy IP of the host running the script and set the port of the proxy on GetGo under proxy settings. When the victim downloads any page or file, the program incorrectly parses the response and passes the request to the malicious host, triggering the overflow.
Mitigation:
Ensure that all software is up to date and patched with the latest security updates.