ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
BID:26467
Info
ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26467 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6028 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 15 2007 12:00AM |
| Updated: | Nov 20 2007 06:04PM |
| Credit: | Elazar Broad is credited with the discovery of these issues. |
| Vulnerable: |
ComponentOne FlexGrid 7.1 Light |
| Not Vulnerable: | |
Discussion
ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
ComponentOne FlexGrid ActiveX Control is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit these issues to cause denial denial-of-service conditions and possibly to execute arbitrary code, but this has not been confirmed.
ComponentOne FlexGrid 7.1 Light is vulnerable; other versions may also be affected.
ComponentOne FlexGrid ActiveX Control is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to adequately check boundaries on user-supplied input.
An attacker can exploit these issues to cause denial denial-of-service conditions and possibly to execute arbitrary code, but this has not been confirmed.
ComponentOne FlexGrid 7.1 Light is vulnerable; other versions may also be affected.
Exploit / POC
ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious webpage.
The following proof of concept is available:
To exploit these issues, an attacker must entice an unsuspecting user to view a malicious webpage.
The following proof of concept is available:
Solution / Fix
ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
ComponentOne FlexGrid ActiveX Control Multiple Buffer Overflow Vulnerabilities
References:
References:
- ComponentOne Homepage (ComponentOne)
- Microsoft Knowledge Base Article 240797 (Microsoft)