AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
BID:11341
Info
AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 11341 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2004 12:00AM |
| Updated: | Sep 15 2004 12:00AM |
| Credit: | Discovery of this issue is credited to Mark Litchfield and John Heasman of NGSSoftware. |
| Vulnerable: |
AtHoc Toolbar |
| Not Vulnerable: | |
Discussion
AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
AtHoc Toolbar is affected by multiple code execution vulnerabilities. These issues exist in an ActiveX component supplied with AtHoc. The vulnerabilities are due to a failure to verify the lengths of user supplied strings prior to copying them into finite process buffers and to a failure to sanitize input prior to passing it as the format specifier string of a formatted printing function.
This issue affects the AtHoc toolbar applications distributed by the following vendors: eBay, Accenture, ThomasRegister, ThomasRegional, Juniper Networks, WiredNews, CarFax, and Agile PLM.
An attacker may leverage these issues to execute arbitrary code on the affected computer with the privileges of the user that activated the vulnerable application.
AtHoc Toolbar is affected by multiple code execution vulnerabilities. These issues exist in an ActiveX component supplied with AtHoc. The vulnerabilities are due to a failure to verify the lengths of user supplied strings prior to copying them into finite process buffers and to a failure to sanitize input prior to passing it as the format specifier string of a formatted printing function.
This issue affects the AtHoc toolbar applications distributed by the following vendors: eBay, Accenture, ThomasRegister, ThomasRegional, Juniper Networks, WiredNews, CarFax, and Agile PLM.
An attacker may leverage these issues to execute arbitrary code on the affected computer with the privileges of the user that activated the vulnerable application.
Exploit / POC
AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
Solution:
The vendor has released an upgrade dealing with these issues.
Users of any of the affected sites listed in the summary are advised to acquire the latest version of the affected toolbar from the respective distributor.
Solution:
The vendor has released an upgrade dealing with these issues.
Users of any of the affected sites listed in the summary are advised to acquire the latest version of the affected toolbar from the respective distributor.
References
AtHoc ToolBar Multiple Remote Code Execution Vulnerabilities
References:
References:
- AtHoc Home Page (AtHoc)
- Toolbar Home Page (AtHoc)
- Multiple Vulnerabilities in the AtHoc Toolbar For MSIE ("NGSSoftware Insight Security Research"
)