AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
BID:26814
Info
AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
| Bugtraq ID: | 26814 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6327 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Jan 11 2008 04:29AM |
| Credit: | shinnai discovered this vulnerability. |
| Vulnerable: |
AVS Media AVSMJPEGFILE.DLL 1.1.1 .102 |
| Not Vulnerable: | |
Discussion
AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
An ActiveX control used in AVS Media software is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
AVSMJPEGFILE.DLL 1.1.1.102 is vulnerable to this issue; other versions may also be affected. This control may be included in multiple AVS Media applications.
An ActiveX control used in AVS Media software is prone to a buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
AVSMJPEGFILE.DLL 1.1.1.102 is vulnerable to this issue; other versions may also be affected. This control may be included in multiple AVS Media applications.
Exploit / POC
AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
A proof of concept is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious webpage.
A proof of concept is available:
Solution / Fix
AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
AVS Media AVSMJPEGFILE.DLL ActiveX Control Remote Buffer Overflow Denial of Service Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (AVS Media)