RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
BID:24883
Info
RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 24883 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2007 12:00AM |
| Updated: | Aug 20 2007 08:53PM |
| Credit: | Will Dormann is credited with the discovery of these issues. |
| Vulnerable: |
Zenturi Zenturi ProgramChecker ActiveX Control 0 |
| Not Vulnerable: | |
Discussion
RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
The Zenturi ProgramChecker 'sasatl.dll' ActiveX control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
RETIRED: This BID is being retired because the issue is already tracked under BID 24274.
The Zenturi ProgramChecker 'sasatl.dll' ActiveX control is prone to a buffer-overflow vulnerability because it fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
RETIRED: This BID is being retired because the issue is already tracked under BID 24274.
Exploit / POC
RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
This issue may be triggered using a browser.
Sample exploit code has been provided:
This issue may be triggered using a browser.
Sample exploit code has been provided:
Solution / Fix
RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
RETIRED: Zenturi ProgramChecker SASATL.DLL ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Zenturi ProgramChecker ActiveX Control Web Site (Zenturi)