SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
BID:27059
Info
SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 27059 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6605 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 28 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | shinnai discovered this issue. |
| Vulnerable: |
SkyFex SkyFex Client 1.0.2 .77 |
| Not Vulnerable: | |
Discussion
SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
SkyFex Client is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks of user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the application using the affected control (typically Internet Explorer). Successful attacks can compromise the application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
SkyFex Client 1.0.2.77 is vulnerable; other versions may also be affected.
SkyFex Client is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks of user-supplied input before copying it to an insufficiently sized memory buffer.
Attackers can exploit this issue to execute arbitrary code in the context of the application using the affected control (typically Internet Explorer). Successful attacks can compromise the application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
SkyFex Client 1.0.2.77 is vulnerable; other versions may also be affected.
Exploit / POC
SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious web document.
The following proof-of-concept code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious web document.
The following proof-of-concept code is available:
Solution / Fix
SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SkyFex Client ActiveX Control 'start' Method Stack Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (SkyFex)