This application requires Javascript for optimal performance.

Orbit.Downloader.Log.Buffer.Overflow

Release Date

Apr 01, 2009

Severity

critical

Impact

Orbit Downloader 2.8.2 and 2.8.3

Description

This indicates an attack attempt against a buffer-overflow vulnerability in Orbit Downloader.

The vulnerability is caused by an error when the vulnerable software handles a malicious long host name. It allows a remote attacker to execute arbitrary code by enticing the user to open a specially crafted URI.

Affected Products

System Compromise: Remote attackers can gain control of the vulnerable system

Recommended Actions

Upgrade to the latest version 2.8.5, available from the following web site:
http://www.orbitdownloader.com/download.htm

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-0187

Reference/s

http://www.securityfocus.com/bid/33894 (BugTraq)

Reference: VID-17348