CVE-2010-0995: Buffer Overflow
Published May 5, 2010
·Updated
Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.
Affected Software
1 affected component
Tonec Internet Download Manager<=5.18
Event History
May 5, 2010
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 6, 2010
Data Sourced
via NVD·02:53 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0995?
CVE-2010-0995 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2010-0995?
To fix CVE-2010-0995, upgrade Internet Download Manager to version 5.19 or later.
3
What types of attacks does CVE-2010-0995 enable?
CVE-2010-0995 enables remote attackers to execute arbitrary code via a specially crafted FTP URI.
4
Which versions of Internet Download Manager are affected by CVE-2010-0995?
Versions of Internet Download Manager prior to 5.19 are affected by CVE-2010-0995.
5
How does CVE-2010-0995 exploit the system?
CVE-2010-0995 exploits the system through a stack-based buffer overflow triggered by specific test sequences sent between client and server.