Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
BID:24959
Info
Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
| Bugtraq ID: | 24959 |
| Class: | Design Error |
| CVE: |
CVE-2007-3883 CVE-2011-1207 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2007 12:00AM |
| Updated: | May 24 2011 10:51AM |
| Credit: | shinnai is credited with the discovery of this vulnerability. |
| Vulnerable: |
Legacy Family Tree Legacy Family Tree 7.5.0.77 IBM Rational System Architect 11.4.0.0 IBM Rational System Architect 11.3.0.0 Data Dynamics ActiveBar ActiveX Control 3.2 Data Dynamics ActiveBar ActiveX Control 3.1 |
| Not Vulnerable: |
IBM Rational System Architect 11.4.0.3 IBM Rational System Architect 11.3.1.4 |
Discussion
Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
Data Dynamics ActiveBar ActiveX control is prone to multiple vulnerabilities caused by insecure methods. The problem stems from a design error in the affected application.
An attacker can exploit this issue to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in a denial-of-service condition.
These issues affect Data Dynamics ActiveBar 3.1; other versions may also be affected.
Data Dynamics ActiveBar ActiveX control is prone to multiple vulnerabilities caused by insecure methods. The problem stems from a design error in the affected application.
An attacker can exploit this issue to overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will likely result in a denial-of-service condition.
These issues affect Data Dynamics ActiveBar 3.1; other versions may also be affected.
Exploit / POC
Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploits are available:
To exploit this issue, an attacker must entice an unsuspecting user to view a maliciously crafted web page.
The following exploits are available:
Solution / Fix
Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Data Dynamics ActiveBar Actbar3.OCX ActiveX Control Multiple Insecure Methods Vulnerabilities
References:
References:
- Data Dynamics Web Site (Data Dynamics)
- Rational System Architect ActiveBar ActiveX Control Vulnerabilities (IBM)
- Vendor Homepage (Legacy Family Tree)