Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:27271
Info
Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27271 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4664 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 11 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | This issue has been reported on the http://hi.baidu.com/muma_reader blog. |
| Vulnerable: |
QVOD Technology QVOD Player 2.1.5 |
| Not Vulnerable: |
QVOD Technology QVOD Player 2.1.5 build 0053 |
Discussion
Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Qvod Player 'QvodInsert.dll' ActiveX control is prone to is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
The issue affects versions prior to Qvod Player 2.1.5 build 0053.
Qvod Player 'QvodInsert.dll' ActiveX control is prone to is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
The issue affects versions prior to Qvod Player 2.1.5 build 0053.
Exploit / POC
Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Reports indicate that this issue is being actively exploited in the wild.
Reports indicate that this issue is being actively exploited in the wild.
Solution / Fix
Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
QVOD Technology QVOD Player 2.1.5
Solution:
The vendor has released an update to address this issue. Please see the references for more information.
QVOD Technology QVOD Player 2.1.5
-
QVOD Technology QVOD Player
http://update.qvod.com/QvodSetup.exe
References
Qvod Player 'QvodInsert.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Newest Qvod the Player player overflow (MuMa_Reader)
- Pigs fly... oh, and another 0-day ... ho hum (Roger Thompson)
- QVOD Player Homepage (QVOD Technology)