BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
BID:26824
Info
BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
| Bugtraq ID: | 26824 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 11 2007 12:00AM |
| Updated: | Dec 13 2007 03:32PM |
| Credit: | Lionel d'Hauenens & Brian Mariani of Syseclabs are credited with the discovery of this vulnerability. |
| Vulnerable: |
BitDefender Total Security 2008 0 BitDefender Internet Security 2008 0 BitDefender Antivirus 2008 0 |
| Not Vulnerable: | |
Discussion
BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
A BitDefender Antivirus 2008 ActiveX control is prone a double-free vulnerability because of a flaw in the way that the 'bdelev.dll' library handles certain object data prior to returning it.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
A BitDefender Antivirus 2008 ActiveX control is prone a double-free vulnerability because of a flaw in the way that the 'bdelev.dll' library handles certain object data prior to returning it.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious web document.
The following proof-of-concept code is available:
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious web document.
The following proof-of-concept code is available:
Solution / Fix
BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
BitDefender Internet Security 2008 0
BitDefender Antivirus 2008 0
BitDefender Total Security 2008 0
Solution:
The vendor released fixes to address this issue. Please see the references for more information.
BitDefender Internet Security 2008 0
-
BitDefender bitdefender_2008/x64/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x64/weekly.ex e -
BitDefender bitdefender_2008/x86/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x86/weekly.ex e
BitDefender Antivirus 2008 0
-
BitDefender bitdefender_2008/x64/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x64/weekly.ex e -
BitDefender bitdefender_2008/x86/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x86/weekly.ex e
BitDefender Total Security 2008 0
-
BitDefender bitdefender_2008/x64/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x64/weekly.ex e -
BitDefender bitdefender_2008/x86/weekly.exe
http://download.bitdefender.com/updates/bitdefender_2008/x86/weekly.ex e
References
BitDefender Antivirus 2008 bdelev.dll ActiveX Control Double Free Vulnerability
References:
References:
- BitDefender Homepage (BitDefender)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- BitDefender 2008 Double Free Vulnerability (Syseclabs)