Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
BID:26536
Info
Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 26536 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6144 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 17 2007 12:00AM |
| Updated: | Dec 18 2007 08:06PM |
| Credit: | This vulnerability was reported on SEBUG.net. |
| Vulnerable: |
Xunlei Thunder 5.7.4 .401 |
| Not Vulnerable: | |
Discussion
Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
Xunlei Thunder PPlayer ActiveX Control is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Thunder 5.7.4.401; other versions may also be vulnerable.
Xunlei Thunder PPlayer ActiveX Control is prone a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Thunder 5.7.4.401; other versions may also be vulnerable.
Exploit / POC
Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
This issue is currently being actively exploited in the wild.
Exploit code has been published on various websites.
Please note that this code can be harmful; Symantec has not verified it.
This issue is currently being actively exploited in the wild.
Exploit code has been published on various websites.
Please note that this code can be harmful; Symantec has not verified it.
Solution / Fix
Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Xunlei Thunder PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- NOHACK Advisory (NOHACK)
- Thunder 5 0-Day (SEBUG.net)