Short Name |
HTTP:STC:ORBIT-DL-URL |
---|---|
Severity |
High |
Recommended |
No |
Category |
HTTP |
Keywords |
Orbit Downloader Long URL Stack Buffer Overflow |
Release Date |
2011/07/18 |
Update Number |
1956 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
A buffer overflow vulnerability exists in Orbit Downloader. The vulnerability is caused due to insufficient boundary checking in the URL string processing. An attacker may exploit this vulnerability by enticing a target user to open a malicious long URL. Successful exploitation might lead to injection and execution of arbitrary code in the security context of the currently logged in user. If code execution is successful, the behaviour of the target will depend on the intention of the injected code. Otherwise, Orbit Downloader may terminate abnormally.
Orbit Downloader is prone to a remote buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the application. Failed exploit attempts will cause a denial-of-service condition. This issue affects versions prior to Orbit Downloader 2.8.5.