Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
BID:27995
Info
Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
| Bugtraq ID: | 27995 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1044 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | Elazar Broad discovered this vulnerability. |
| Vulnerable: |
Move Networks Quantum Streaming qsp2ie07074039.dll 7.7.4.39 |
| Not Vulnerable: | |
Discussion
Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
Move Media Player Quantum Streaming 'qsp2ie07074039.dll' ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control (typically Internet Explorer) and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
This issue affects Quantum Streaming 'qsp2ie07074039.dll' ActiveX control 7.7.4.39; other versions may also be vulnerable.
Move Media Player Quantum Streaming 'qsp2ie07074039.dll' ActiveX control is prone to a remote buffer-overflow vulnerability because the application fails to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of applications using the affected ActiveX control (typically Internet Explorer) and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
This issue affects Quantum Streaming 'qsp2ie07074039.dll' ActiveX control 7.7.4.39; other versions may also be vulnerable.
Exploit / POC
Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious HTML page.
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious HTML page.
Solution / Fix
Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Move Media Player Quantum Streaming 'qsp2ie07074039.dl ActiveX Control Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Move Networks Homepage (Move Networks)