Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
BID:19810
CVE-2006-4555 |Info
Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 19810 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 01 2006 12:00AM |
| Updated: | Sep 05 2006 11:43PM |
| Credit: | Discovered by Will Dormann of CERT/CC. |
| Vulnerable: |
Retro64 CR64Loader 0 |
| Not Vulnerable: | |
Discussion
Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
The Retro64 CR64Loader ActiveX control is prone to a remote buffer-overflow vulnerability.
To exploit this issue, attackers require users to visit malicious HTML content. A successful exploit would allow a remote attacker to execute code with the privileges of the targeted user.
The vulnerable control was distributed in the past by retro64.com and miniclip.com, but is reportedly no longer in use. Users who have previously installed this software may be vulnerable to this issue.
The Retro64 CR64Loader ActiveX control is prone to a remote buffer-overflow vulnerability.
To exploit this issue, attackers require users to visit malicious HTML content. A successful exploit would allow a remote attacker to execute code with the privileges of the targeted user.
The vulnerable control was distributed in the past by retro64.com and miniclip.com, but is reportedly no longer in use. Users who have previously installed this software may be vulnerable to this issue.
Exploit / POC
Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Retro64 CR64Loader ActiveX Remote Buffer Overflow Vulnerability
References:
References:
- Miniclip Home Page (Miniclip)
- Retro64 Home Page (Retro64)
- Vulnerability Note VU#649289 (US-CERT)