ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
BID:22558
Info
ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 22558 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-0976 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | shinnai is credited with the discovery of this vulnerability. |
| Vulnerable: |
ActiveX Soft ActSoft DVD Tools 3.8.5 |
| Not Vulnerable: | |
Discussion
ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
ActSoft DVD Tools is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker may exploit this issue by enticing victims into opening a malicious HTML document.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
ActSoft DVD Tools is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker may exploit this issue by enticing victims into opening a malicious HTML document.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
Exploit / POC
ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept and exploit are available:
Solution / Fix
ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
ActSoft DVD-Tools DVDTools.OCX ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- ActSoft DVD Tools Homepage (ActiveX Soft)
- Microsoft Knowledge Base Article 240797 (Microsoft)