eForm
09-04-2004, 10:14 AM
Source : Flexbeta (http://www.flexbeta.net/main/comments.php?catid=11&shownews=9102)
A vulnerability in the Altnet Download Manager included in Kazaa has been reported by CelebrityHacker. The vulnerability is caused due to a boundary error within the "IsValidFile()" method in the ADM ActiveX control. This can be exploited to cause a stack-based buffer overflow via e.g. a malicious web site by passing an overly long string to the "bstrFilepath" parameter. In short, an attacker can execute arbritary code if seccessful. The vulnerability has been confirmed in Altnet Download Manager 4.0.0.4 included in Kazaa 2.7.1. Other versions may also be affected. The cure,according to Secunia (http://secunia.com/advisories/12455/), is to remove the Altnet Download Manager ("adm.exe") or uninstall Kazaa.
A vulnerability in the Altnet Download Manager included in Kazaa has been reported by CelebrityHacker. The vulnerability is caused due to a boundary error within the "IsValidFile()" method in the ADM ActiveX control. This can be exploited to cause a stack-based buffer overflow via e.g. a malicious web site by passing an overly long string to the "bstrFilepath" parameter. In short, an attacker can execute arbritary code if seccessful. The vulnerability has been confirmed in Altnet Download Manager 4.0.0.4 included in Kazaa 2.7.1. Other versions may also be affected. The cure,according to Secunia (http://secunia.com/advisories/12455/), is to remove the Altnet Download Manager ("adm.exe") or uninstall Kazaa.