Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
BID:26537
Info
Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
| Bugtraq ID: | 26537 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2007 12:00AM |
| Updated: | Aug 25 2008 03:55PM |
| Credit: | Elazar Broad is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Aurigma ImageUploader 4.5.50 .0 Aurigma ImageUploader 4.1.21 .0 Aurigma ImageUploader 4.1.20 Aurigma Image Uploader 4.1 |
| Not Vulnerable: |
Aurigma ImageUploader 4.5.70 |
Discussion
Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
Aurigma Image Uploader ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Aurigma Image Uploader 4.5.70 are affected.
UPDATE (November 26, 2007): Reports indicate that this issue occurs because of a buffer-overflow issue that affects a Win32API method. This has not been confirmed. We will update this BID as more information emerges.
Aurigma Image Uploader ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Aurigma Image Uploader 4.5.70 are affected.
UPDATE (November 26, 2007): Reports indicate that this issue occurs because of a buffer-overflow issue that affects a Win32API method. This has not been confirmed. We will update this BID as more information emerges.
Exploit / POC
Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
The following proof-of-concept example is available:
The following proof-of-concept example is available:
Solution / Fix
Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
Solution:
The vendor released Image Uploader 5.5.70 to address this issue. Please contact the vendor for information on how to obtain and apply fixes.
Solution:
The vendor released Image Uploader 5.5.70 to address this issue. Please contact the vendor for information on how to obtain and apply fixes.
References
Aurigma Image Uploader ActiveX Control Multiple Remote Stack Buffer Overflow Vulnerabilities
References:
References:
- Aurigma Image Uploader Homepage (Aurigma)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Advisory (953839) Cumulative Security Update of ActiveX Kill (Microsoft)
- Security issue in Image Uploader (Aurigma)