PT-2017-3363 · Getgo · Getgo Download Manager

Aloyce J. Makalanga

·

Publicado

2017-12-24

·

Atualizado

2018-07-28

·

CVE-2017-17849

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetGo Download Manager versions 5.3.0.2712 and earlier
Description A buffer overflow issue could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response. The vulnerability can be exploited by a remote attacker using a specially crafted string in the HTTP response header, potentially leading to the execution of arbitrary code on the device.
Recommendations For GetGo Download Manager versions 5.3.0.2712 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00134
CVE-2017-17849

Produtos afetados

Getgo Download Manager