Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
BID:27576
Info
Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
| Bugtraq ID: | 27576 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0660 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Elazar Broad discovered these vulnerabilities. |
| Vulnerable: |
Facebook ImageUploader4.ocx 4.5.57 .0 Facebook ImageUploader4.1.ocx 4.5.57 .0 |
| Not Vulnerable: |
Facebook ImageUploader4.ocx 4.5.57 .1 |
Discussion
Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
Facebook Photo Uploader ActiveX control is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
The issues affect 'ImageUploader4.ocx' 4.5.57.0; other versions may also be vulnerable.
NOTE: 'ImageUploader4.ocx' 4.5.57.0 may also be installed as 'ImageUploader4.1.ocx'.
Facebook Photo Uploader ActiveX control is prone to multiple buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
The issues affect 'ImageUploader4.ocx' 4.5.57.0; other versions may also be vulnerable.
NOTE: 'ImageUploader4.ocx' 4.5.57.0 may also be installed as 'ImageUploader4.1.ocx'.
Exploit / POC
Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
Solution:
Reportedly, the 'ImageUploader4.ocx' control 4.5.57.1 is not affected by the issues, but this has not been confirmed by Symantec or the vendor. Customers should contact the vendor for information on obtaining and applying fixes.
Solution:
Reportedly, the 'ImageUploader4.ocx' control 4.5.57.1 is not affected by the issues, but this has not been confirmed by Symantec or the vendor. Customers should contact the vendor for information on obtaining and applying fixes.
References
Facebook Photo Uploader 4 ActiveX Control 'ExtractIptc/ExtractExif' Buffer Overflow Vulnerabilities
References:
References:
- Facebook Homepage (Facebook)
- Microsoft Knowledge Base Article 240797 (Microsoft)