Lucene search

K
saintSAINT CorporationSAINT:295AEDC59D4D17030655E28355D5B0DB
HistoryJan 10, 2012 - 12:00 a.m.

CoCSoft Stream Down Stack Overflow

2012-01-1000:00:00
SAINT Corporation
my.saintcorporation.com
17

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.065

Percentile

93.9%

Added: 01/10/2012
CVE: CVE-2011-5052
BID: 51190
OSVDB: 78043

Background

CoCSoft Stream Down is a streaming media download tool.

Problem

The CoCSoft Stream Down HTTP client implementation in version 6.8 and prior does not properly validate HTTP responses. This vulnerability may allow an attacker to trick a user into downloading a specially crafted malicious stream which may result in giving the attacker control of execution on the target system.

Resolution

No updates are available at this time.

References

<http://www.stream-down.cocsoft.com/&gt;

Limitations

This exploit has been tested against CoCSoft Stream Down 6.6.0 on Windows XP SP3 English (DEP OptIn) and Windows 7 SP1 (DEP OptIn).

Platforms

Windows

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.065

Percentile

93.9%

Related for SAINT:295AEDC59D4D17030655E28355D5B0DB