Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
BID:23554
Info
Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 23554 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-1690 CVE-2007-1691 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 18 2007 12:00AM |
| Updated: | Apr 24 2007 05:10PM |
| Credit: | Will Dormann of CERT/CC is credited with discovering these issues. |
| Vulnerable: |
Second Sight Software ActiveMod 0 Second Sight Software ActiveGS 0 |
| Not Vulnerable: | |
Discussion
Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
Second Sight Software ActiveGS and ActiveMod ActiveX controls are prone to multiple buffer-overflow vulnerabilities because the software fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX controls and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
Second Sight Software ActiveGS and ActiveMod ActiveX controls are prone to multiple buffer-overflow vulnerabilities because the software fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
Exploiting these issues allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX controls and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
Exploit / POC
Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
The following proof-of-concept examples are available:
The following proof-of-concept examples are available:
Solution / Fix
Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Second Sight Software Multiple ActiveX Controls Multiple Buffer Overflow Vulnerabilities
References:
References:
- Second Sight Software Homepage (Second Sight Software)
- Vulnerability Note VU#962305 (US-CERT)
- Vulnerability Note VU#118737 (US-CERT)