Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Preemptive Protection against Free Download Manager Remote Control Server

Subscribe

Check Point Reference: CPAI-2009-051
Date Published:
Severity:
Source: Secunia Research
Industry Reference(s): CVE-2009-0183
CVE-2008-2234
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Free Download Manager 2.5 Build 758
Free Download Manager 3.0 Build 844
Vulnerability Description
A buffer overflow vulnerability was reported in Free Download Manager, a free download accelerator and manager. The vulnerability is caused due to a boundary error in the Remote Control Server when processing "Authorization" headers in HTTP requests. This issue can be triggered via an HTTP request containing an overly long "Authorization" header. Successful exploitation allows execution of arbitrary code.
Update/Patch Available
Upgrade to Free Download Manager version 3.0 build 848 :
http://www.freedownloadmanager.org/download.htm
Vulnerability Details
The vulnerability is caused due to a boundary error in the Remote Control Server when processing "Authorization" headers in HTTP requests. Sending a crafted HTTP request can be exploited to cause a stack-based buffer overflow that may result in arbitrary code execution.

Protection Overview
Users of IPS-1 are preemptive against this vulnerability if they have activated the protection against Openwsman Authentication Buffer Overflow released in November 2008 (CPAI-2008-235). IPS-1 detects and blocks HTTP requests with long Authorization headers.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Web Intelligence > WWW 2, and select the CGI Attacks protection group.
3. Click Openwsman Basic Authentication Buffer Overflow (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: WWW/CGI Attacks Protection Group
Description: Openwsman Basic Authentication Buffer Overflow