vendor:
DAP
by:
Krystian Kloskowski (h07)
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: DAP
Affected Version From: DAP version 8.x
Affected Version To: DAP version 8.x
Patch Exists: NO
Related CWE:
CPE: a:download_accelerator_plus:dap:8.x
Platforms Tested: Windows XP English sp2&sp3
DAP 8.x (.m3u) File BOF C Exploit for XP SP2,SP3 English
This exploit targets a buffer-overflow vulnerability in Download Accelerator Plus (DAP) version 8.x. The vulnerability allows remote attackers to execute arbitrary code in the context of the application. By creating a specially crafted .m3u file, an attacker can trigger a buffer overflow and exploit the vulnerability. The exploit code is written in C and was developed by Shinnok (raydenxy [at] yahoo dot com). The original proof-of-concept was discovered by Krystian Kloskowski (h07) <h07@interia.pl>.
Mitigation:
Apply the latest patch provided by the vendor.