Gadu-Gadu 6.0 - File Download Filename Obfuscation
Author: Bartosz Kwitkowski
type: remote
platform: windows
port:
date_added: 2004-08-23
date_updated: 2013-01-27
verified: 1
codes: CVE-2004-2530;OSVDB-9162
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/11017/info
Gadu-Gadu is a Polish instant messaging application for Microsoft Windows operating systems.
It is reported that the Gadu-Gadu instant messenger application contains a weakness allowing attackers to obfuscate file extensions.
This may allow an attacker to send potentially malicious executable files to users who think that they are downloading files that are believed to be harmless.
file.ext%20(220%20kB)%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20.exe