PDA

View Full Version : Orbit Downloader "Download Failed" Buffer Overflow



newsbot
06-04-2008, 03:53 PM
Orbit downloader (http://www.orbitdownloader.com/) is vulnerable to a buffer overflow attack, which can be exploited by malicious remote attackers to execute arbitrary code. The vulnerability is due to Orbit not properly converting an URL ascii string to unicode. This can be exploited to execute arbitrary code by downloading a file from a specially crafted URL.

http://www.securiteam.com/windowsntfocus/5TP011PO1C.html