Vulnerability CVE-2017-17849


Published: 2017-12-27

Description:
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.

See advisories in our WLB2 database:
Topic
Author
Date
High
GetGo Download Manager 5.3.0.2712 Buffer Overflow
Aloyce J. Makala...
25.12.2017
Med.
GetGo Download Manager 6.2.1.3200 Buffer Overflow (Denial of Service)
Nathu Nandwani
25.07.2018

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

Vendor: Getgosoft
Product: Getgo download manager 
Version: 5.3.0.2712;

CVSS2 => (AV:N/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
10/10
10/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://packetstormsecurity.com/files/145530/GetGo-Download-Manager-5.3.0.2712-Buffer-Overflow.html
https://www.exploit-db.com/exploits/43391/
https://www.exploit-db.com/exploits/45087/

Copyright 2019, cxsecurity.com

 

Back to Top