[原文]Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 18.104.22.168 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter.
A remote overflow exists in Altnet Download Manager. The Altnet Download Manager's ActiveX control fails to validate input in the isValidFile() function, causing a long string to the bstrFilepath variable, resulting in a stack based overflow. With a specially crafted request, an attacker can cause execution of arbitrary code resulting in a loss of integrity.
Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround(s):
Remove the adm.exe (altnet download manager) executable.