CVE-2008-4508
Internet Download Manager - Stack-based Buffer Overflow via Crafted AppleDouble File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4508. PoCs published by Ciph3r.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Internet Download Manager (IDM) by sending a maliciously crafted email with an oversized filename in the Content-Disposition header. The payload includes a structured AppleDouble header and a large buffer designed to overwrite memory and potentially execute arbitrary code.
Description
Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. NOTE: this is probably a different vulnerability than CVE-2005-2210.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Internet Download Manager (IDM) by sending a maliciously crafted email with an oversized filename in the Content-Disposition header. The payload includes a structured AppleDouble header and a large buffer designed to overwrite memory and potentially execute arbitrary code.