Namo Web Editor 'NamoInstaller.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:27580
Info
Namo Web Editor 'NamoInstaller.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27580 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0551 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Plan-S discovered this vulnerability. |
| Vulnerable: |
SJ Namo Web Editor ActiveSquare ActiveX Control 6 |
| Not Vulnerable: | |
Discussion
Namo Web Editor 'NamoInstaller.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Namo Web Editor 'NamoInstaller.dll' ActiveX Control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
'NamoInstaller.dll' 3.0.0.1 is vulnerable to this issue; other versions may also be affected.
NOTE: This control is also vulnerable to the remote command-execution issue described in BID 27453.
Namo Web Editor 'NamoInstaller.dll' ActiveX Control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
'NamoInstaller.dll' 3.0.0.1 is vulnerable to this issue; other versions may also be affected.
NOTE: This control is also vulnerable to the remote command-execution issue described in BID 27453.
Exploit / POC
Namo Web Editor 'NamoInstaller.dll' ActiveX Control Remote Buffer Overflow Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
References
Namo Web Editor 'NamoInstaller.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Web Editor Product Page (SJ Namo)