GetGo Download Manager HTTP Headers Processing Buffer Overflow Vulnerability


Description   RCE Security has discovered a vulnerability in GetGo Download Manager, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to a boundary error when processing HTTP response headers, which can be exploited to cause a stack-based buffer overflow via a specially crafted HTTP response.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is confirmed in version 4.9.0.1982. Other versions may also be affected.
     
Vulnerable Products   Vulnerable Software:
GetGo Download Manager 4.x
     
Solution   No official solution is currently available.
     
CVE   CVE-2014-2206
     
References   RCE Security:
http://www.rcesecurity.com/2014/03/cve-2014-2206-getgo-download-manager-http-response-header-buffer-overflow-remote-code-execution/
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
High 

 Vulnerability First Public Report Date 
2014-03-07 

 Target Type 
Server 

 Possible exploit 
Remote