Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:27715
Info
Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 27715 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0748 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 10 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Trancek discovered this vulnerability. |
| Vulnerable: |
Sony ImageStation AxRUploadServer.dll 1.0.0.38 |
| Not Vulnerable: | |
Discussion
Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Sony ImageStation ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects 'AxRUploadServer.dll' 1.0.0.38; other versions may also be vulnerable.
Sony ImageStation ActiveX control is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
This issue affects 'AxRUploadServer.dll' 1.0.0.38; other versions may also be vulnerable.
Exploit / POC
Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
UPDATE (March 26, 2008): The Symantec DeepSight Team has discovered active exploits in the wild.
The following proof of concept and exploit are available:
UPDATE (March 26, 2008): The Symantec DeepSight Team has discovered active exploits in the wild.
The following proof of concept and exploit are available:
Solution / Fix
Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sony ImageStation 'AxRUploadServer.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- ImageStation Homepage (Sony)
- Microsoft Knowledge Base Article 240797 (Microsoft)