Adobe Download Manager < 2.2 AOM File Handling Section Name Overflow

medium Nessus Plugin ID 23779


The remote Windows host has an application that is prone to a buffer overflow attack.


There is a version Adobe Download Manager installed on the remote Windows host that is vulnerable to a remote buffer overflow attack because the application fails to perform boundary checks while processing AOM files. In order to trigger this issue, an attacker needs to entice a user to visit a website hosting the malicious AOM file or send the AOM file as an email attachment and have the user click on it. Successful exploitation of this issue might result in arbitrary code execution.


Either uninstall the application or upgrade to Adobe Download Manager version 2.2 or later.

See Also

Plugin Details

Severity: Medium

ID: 23779

File Name: adobe_aom_buffer_overflow_vulnerability.nasl

Version: 1.19

Type: local

Agent: windows

Family: Windows

Published: 12/7/2006

Updated: 11/15/2018

Supported Sensors: Nessus Agent

Risk Information


Risk Factor: Medium

Score: 5.5


Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: E:U/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:download_manager

Required KB Items: SMB/Registry/Enumerated

Exploit Ease: No known exploits are available

Patch Publication Date: 12/5/2006

Vulnerability Publication Date: 12/6/2006

Reference Information

CVE: CVE-2006-5856

BID: 21453