Description
Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads menu, causes a buffer overflow in the Location header response that overwrites the SEH chain and executes arbitrary code.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Marwan Shamel
References
www.exploit-db.com/exploits/44499 (ExploitDB-44499)
filehippo.com/download_free_download_manager/925/ (Product Reference)
www.vulncheck.com/...ger-built-417-local-buffer-overflow-seh (VulnCheck Advisory: Free Download Manager 2.0 Built 417 Local Buffer Overflow SEH)