Adobe Download Manager < 2.2 AOM File Handling Section Name Overflow

Medium Nessus Plugin ID 23779


The remote Windows host has an application that is prone to a buffer overflow attack.


There is a version Adobe Download Manager installed on the remote Windows host that is vulnerable to a remote buffer overflow attack because the application fails to perform boundary checks while processing AOM files. In order to trigger this issue, an attacker needs to entice a user to visit a website hosting the malicious AOM file or send the AOM file as an email attachment and have the user click on it. Successful exploitation of this issue might result in arbitrary code execution.


Either uninstall the application or upgrade to Adobe Download Manager version 2.2 or later.

See Also

Plugin Details

Severity: Medium

ID: 23779

File Name: adobe_aom_buffer_overflow_vulnerability.nasl

Version: $Revision: 1.17 $

Type: local

Agent: windows

Family: Windows

Published: 2006/12/07

Modified: 2016/09/23

Dependencies: 13855

Risk Information

Risk Factor: Medium


Base Score: 6.8

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:U/RL:W/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:download_manager

Required KB Items: SMB/Registry/Enumerated

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2006/12/05

Vulnerability Publication Date: 2006/12/06

Reference Information

CVE: CVE-2006-5856

BID: 21453

OSVDB: 31055