PDA

View Full Version : Kazaa Highly Critical Security Vulnerability


eForm
09-04-2004, 10:14 AM
Source : Flexbeta (http://www.flexbeta.net/main/comments.php?catid=11&shownews=9102)

A vulnerability in the Altnet Download Manager included in Kazaa has been reported by CelebrityHacker. The vulnerability is caused due to a boundary error within the "IsValidFile()" method in the ADM ActiveX control. This can be exploited to cause a stack-based buffer overflow via e.g. a malicious web site by passing an overly long string to the "bstrFilepath" parameter. In short, an attacker can execute arbritary code if seccessful. The vulnerability has been confirmed in Altnet Download Manager 4.0.0.4 included in Kazaa 2.7.1. Other versions may also be affected. The cure,according to Secunia (http://secunia.com/advisories/12455/), is to remove the Altnet Download Manager ("adm.exe") or uninstall Kazaa.

lordpake
09-05-2004, 04:46 AM
Security vulnerability in Kazaa?? NOo wayy! :laugh: I'd call that whole proggie security vulnerability :squint:

KLITETOOLS
09-10-2004, 02:21 PM
just like to point out that, this problem is with regular kazaa (kmd) and not klite2.4.4 or klt K++ 2.7.0. as they contain no ad/spyware.

in short if you have kazaa (kmd) and not klite or klt on your pc you need your head examined :) :hammered: :hammered:

Project-Buckfast
09-10-2004, 02:39 PM
its good to see ur a full on member nigh KLT ya can keep me up to date!:type:

KLITETOOLS
09-10-2004, 11:05 PM
at your service sir :type:

ToM
09-11-2004, 05:49 PM
According to recent unconfirmed statistics, anyone using Kazaa will already have on average 74 additional exploits on their PC, caused by their inability to use computers and adapt to today's technology.