vendor:
GetGo Download Manager
by:
Nathu Nandwani
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: GetGo Download Manager
Affected Version From: 6.2.1.3200
Affected Version To: 6.2.1.3200
Patch Exists: Yes
Related CWE: CVE-2017-17849
CPE: 2.3:a:getgo_software:getgo_download_manager:6.2.1.3200
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x86, Windows 10 x64
2018
GetGo Download Manager 6.2.1.3200 – Buffer Overflow (Denial of Service)
The downloader feature of GetGo Download Manager is vulnerable to a buffer overflow which can cause a denial of service. To test the proof of concept, have it executed in your machine and let the GetGo application download 'index.html' from your given IP. SEH details (Windows 7 x86): SEH chain of thread 00000644, item 1 Address=0863E2C8 SE handler=68463967 <-> 4108 offset SEH chain of thread 00000644, item 2 Address=46386746 <-> 4104 offset SE handler=*** CORRUPT ENTRY ***
Mitigation:
Ensure that the application is updated to the latest version and all security patches are applied.