IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
BID:19554
CVE-2006-4221 |Info
IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19554 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4221 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 16 2006 12:00AM |
| Updated: | Oct 04 2007 05:08PM |
| Credit: | Discovered by Andre Derek Protas. |
| Vulnerable: |
IBM eGatherer 2.42.243 .0 IBM eGatherer 2.0 .16 |
| Not Vulnerable: |
IBM eGatherer 3.20.284 .0 |
Discussion
IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
IBM eGatherer ActiveX is prone to a stack-based buffer-overflow vulnerability.
This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would allow a remote attacker to execute code with the privileges of the currently logged-in user.
Versions prior to IBM eGatherer ActiveX 3.20.0284.0 are vulnerable.
IBM eGatherer ActiveX is prone to a stack-based buffer-overflow vulnerability.
This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would allow a remote attacker to execute code with the privileges of the currently logged-in user.
Versions prior to IBM eGatherer ActiveX 3.20.0284.0 are vulnerable.
Exploit / POC
IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
The following proof-of-concept and exploit code is available to demonstrate this issue:
The following proof-of-concept and exploit code is available to demonstrate this issue:
Solution / Fix
IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
Solution:
IBM has released eGatherer ActiveX control 3.20.0284.0 to address this issue. Please see the references for more information.
IBM eGatherer 2.0 .16
IBM eGatherer 2.42.243 .0
Solution:
IBM has released eGatherer ActiveX control 3.20.0284.0 to address this issue. Please see the references for more information.
IBM eGatherer 2.0 .16
-
IBM eGatherer 3.20.0284.0
http://www-307.ibm.com/pc/support/IbmEgath.cab
IBM eGatherer 2.42.243 .0
-
IBM eGatherer 3.20.0284.0
http://www-307.ibm.com/pc/support/IbmEgath.cab
References
IBM eGatherer ActiveX Remote Buffer Overflow Vulnerability
References:
References:
- [EEYEB-20060703] IBM eGatherer ActiveX Code Execution Vulnerability ("eEye Advisories"
)