HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
BID:24730
Info
HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
| Bugtraq ID: | 24730 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3554 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | John Heasman of NGSSoftware is credited with the discovery of this vulnerability. |
| Vulnerable: |
HP Instant Support 0 |
| Not Vulnerable: |
HP Instant Support 1.5 3 |
Discussion
HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
HP Instant Support ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and possibly to compromise affected computers.
HP Instant Support ActiveX control is prone to a remote buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control and possibly to compromise affected computers.
Exploit / POC
HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
Solution:
The vendor released updates to address this issue. Please see the references for more information.
Solution:
The vendor released updates to address this issue. Please see the references for more information.
References
HP Instant Support ActiveX Control Driver Check Buffer Overflow Vulnerability
References:
References: