Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
BID:27493
Info
Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
| Bugtraq ID: | 27493 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4584 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | darkl0rd is credited with the discovery of this vulnerability. |
| Vulnerable: |
Chilkat Email 7.8 |
| Not Vulnerable: | |
Discussion
Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
Chilkat Email ActiveX control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits can compromise affected computers or cause denial-of-service conditions; other attacks are possible.
This issue affects the 'ChilkatCert.dll' library of the Chilkat Email ActiveX control 7.8; other versions may also be affected.
Chilkat Email ActiveX control is prone to a vulnerability that allows attackers to create or overwrite arbitrary data with the privileges of the application using the control (typically Internet Explorer).
Successful exploits can compromise affected computers or cause denial-of-service conditions; other attacks are possible.
This issue affects the 'ChilkatCert.dll' library of the Chilkat Email ActiveX control 7.8; other versions may also be affected.
Exploit / POC
Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a specially crafted web document.
The following exploit code is available:
Solution / Fix
Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Chilkat Email 'ChilkatCert.dll' ActiveX Control Insecure Method Vulnerability
References:
References:
- Chilkat Software Homepage (Chilkat Software)
- Microsoft Knowledge Base Article 240797 (Microsoft)