Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
BID:27438
Info
Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 27438 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0477 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 24 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | e.b. discovered this vulnerability. |
| Vulnerable: |
Move Networks Move Media Player 1.0 .1 |
| Not Vulnerable: | |
Discussion
Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
The Move Networks Media Player ActiveX control that is used to manage updates is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Move Media Player 1.0.0.1; other versions may also be vulnerable.
UPDATE (January 28, 2008): Reports indicate that recent versions of the affected application are not vulnerable because the 'QMPUpgrade.dll' is no longer included. However, users who upgraded to a newer version from a vulnerable version may still be affected because the installation process of newer versions leaves the vulnerable library intact. Please see the workaround section for information on how to address this.
The Move Networks Media Player ActiveX control that is used to manage updates is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
This issue affects Move Media Player 1.0.0.1; other versions may also be vulnerable.
UPDATE (January 28, 2008): Reports indicate that recent versions of the affected application are not vulnerable because the 'QMPUpgrade.dll' is no longer included. However, users who upgraded to a newer version from a vulnerable version may still be affected because the installation process of newer versions leaves the vulnerable library intact. Please see the workaround section for information on how to address this.
Exploit / POC
Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious HTML document.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious HTML document.
The following exploit code is available:
Solution / Fix
Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Move Networks Media Player QMPUpgrade.dll ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Move Networks Homepage (Move Networks)
- Move Networks Upgrade Manager QMPUpgrade.dll Buffer Overflow (Elazar Broad
)