SDP Downloader HTTP Header Handling Buffer Overflow Vulnerability


Description   A vulnerability has been identified in SDP Downloader, which could be exploited by attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error when processing overly long HTTP headers e.g. "Content-Type:", which could be exploited by attackers to crash an affected application or execute arbitrary code by convincing a user to download a file from a malicious server.
     
Vulnerable Products   Vulnerable Software:
SDP Downloader version 2.3.0 and prior
     
Solution  
     
CVE  
     
References   http://www.exploit-db.com/exploits/16078/
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2011-01-31 

 Target Type 
Client 

 Possible exploit 
Local & Remote