GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
BID:27626
Info
GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 27626 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0647 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 05 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | These issues were discovered due to active exploit attempts. |
| Vulnerable: |
GlobalLink GlobalLink 2.8.1.2 beta GlobalLink GlobalLink 2.6.1.29 |
| Not Vulnerable: | |
Discussion
GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
GlobalLink is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit these issues to execute arbitrary code within the context of application that invoked the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
These issues affect GlobalLink 2.8.1.2 beta and 2.6.1.29; other versions may also be affected.
GlobalLink is prone to multiple buffer-overflow vulnerabilities because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit these issues to execute arbitrary code within the context of application that invoked the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in a denial-of-service condition.
These issues affect GlobalLink 2.8.1.2 beta and 2.6.1.29; other versions may also be affected.
Exploit / POC
GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
These issues are being exploited in the wild.
The following exploit code is available:
These issues are being exploited in the wild.
The following exploit code is available:
Solution / Fix
GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
GlobalLink 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
References:
References:
- Chinese Weekend Compromise (Trend Micro)
- GlobalLink Homepage (GlobalLink)
- JS_IFRAME.AD (Trend Micro)
- Microsoft Support Document 240797 (Microsoft)