Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
BID:27756
Info
Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
| Bugtraq ID: | 27756 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-5711 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 12 2008 12:00AM |
| Updated: | Dec 31 2008 06:02PM |
| Credit: | Rafel Ivgi, "The-Insider" discovered this vulnerability. |
| Vulnerable: |
Facebook ImageUploader4.ocx 4.5.57 .0 Facebook ImageUploader4.1.ocx 4.5.57 .0 |
| Not Vulnerable: |
Facebook ImageUploader4.ocx 4.5.57 .1 |
Discussion
Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
Facebook Photo Uploader ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
Image Uploader 4.5.57.0 is vulnerable; other versions may also be affected.
Facebook Photo Uploader ActiveX control is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue may allow remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
Image Uploader 4.5.57.0 is vulnerable; other versions may also be affected.
Exploit / POC
Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious web document.
The following exploit code is available:
To exploit this issue, an attacker must entice an unsuspecting user to view a malicious web document.
The following exploit code is available:
Solution / Fix
Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
Solution:
Reports indicate that the vendor addressed the issue. Authenticated Facebook users who create a new album using the affected control will receive the patch. To do this, visit the following URI:
http://www.facebook.com/editalbum.php?aid=<user_album_id>&add=1
NOTE: Symantec has not confirmed the validity of the claims regarding the availability of an official patch and how to obtain the reported patch.
Solution:
Reports indicate that the vendor addressed the issue. Authenticated Facebook users who create a new album using the affected control will receive the patch. To do this, visit the following URI:
http://www.facebook.com/editalbum.php?aid=<user_album_id>&add=1
NOTE: Symantec has not confirmed the validity of the claims regarding the availability of an official patch and how to obtain the reported patch.
References
Facebook Photo Uploader 'ImageUploader4.1.ocx' FileMask Method ActiveX Buffer Overflow Vulnerability
References:
References:
- Facebook Homepage (Facebook)
- Microsoft Knowledge Base Article 240797 (Microsoft)