PT-2014-4475 · Free Download Manager Team · Free Download Manager

Julien Ahrens

·

Published

2014-03-18

·

Updated

2018-10-09

·

CVE-2014-2087

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Free Download Manager versions 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier
Description The issue is related to a stack-based buffer overflow in the CDownloads Deleted::UpdateDownload function. This allows remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
Recommendations For Free Download Manager versions 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier, consider avoiding the use of long file names in the download queue until a fix is available. As a temporary workaround, restrict the ability to delete files from the download queue to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-2087

Affected Products

Free Download Manager