vendor:
Internet Download Manager
by:
Dark-Puzzle (Souhail Hammou)
N/A
CVSS
N/A
Stack Based Buffer Overflow
119
CWE
Product Name: Internet Download Manager
Affected Version From: All versions
Affected Version To: All versions
Patch Exists: YES
Related CWE: N/A
CPE: a:tonec:internet_download_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP Service Pack 2 FR 32-bits
2012
Internet Download Manager All Versions – Stack Based Buffer Overflow Vulnerability.
A stack-based buffer overflow vulnerability exists in all versions of Internet Download Manager (IDM). An attacker can exploit this vulnerability by copying the content of a malicious file into the username field of the IDM Dial Up/VPN options, leaving the password field blank. This will cause a buffer overflow and execute arbitrary code on the target system.
Mitigation:
Upgrade to the latest version of Internet Download Manager.