Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
BID:28010
Info
Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
| Bugtraq ID: | 28010 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-4771 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2008 12:00AM |
| Updated: | Apr 16 2015 06:05PM |
| Credit: | rgod discovered this vulnerability. |
| Vulnerable: |
Vivotek RTSP MPEG4 SP Control 2.0.0.39 D-Link MPEG4 SHM Audio Control 1.7.0.5 4xem VatCtrl Class 1.0.0.51 |
| Not Vulnerable: | |
Discussion
Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
Various IP Security Camera ActiveX controls are prone to a remote buffer-overflow vulnerability because the applications fail to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of applications that use the affected ActiveX control (typically Internet Explorer) and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
This issue affects the following ActiveX controls:
D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5.
4XEM VatCtrl Class ('VATDecoder.dll') 1.0.0.51.
Vivotek RTSP MPEG4 SP Control ('RtspVapgDecoderNew.dll') 2.0.0.39.
UPDATE (March 25, 2008): D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5 identified by CLSID: A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C is being actively exploited in the wild.
Various IP Security Camera ActiveX controls are prone to a remote buffer-overflow vulnerability because the applications fail to properly bounds-check user-supplied data before copying it into insufficiently sized memory buffers.
Exploiting this issue may allow remote attackers to execute arbitrary code in the context of applications that use the affected ActiveX control (typically Internet Explorer) and to compromise affected computers. Failed attempts will likely result in denial-of-service conditions.
This issue affects the following ActiveX controls:
D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5.
4XEM VatCtrl Class ('VATDecoder.dll') 1.0.0.51.
Vivotek RTSP MPEG4 SP Control ('RtspVapgDecoderNew.dll') 2.0.0.39.
UPDATE (March 25, 2008): D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5 identified by CLSID: A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C is being actively exploited in the wild.
Exploit / POC
Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious HTML page.
UPDATE (March 25, 2008): D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5 identified by CLSID: A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C is being actively exploited in the wild.
The following exploit code is available:
An attacker can exploit this issue by enticing an unsuspecting user to view a malicious HTML page.
UPDATE (March 25, 2008): D-Link MPEG4 SHM Audio Control ('VAPGDecoder.dll') 1.7.0.5 identified by CLSID: A93B47FD-9BF6-4DA8-97FC-9270B9D64A6C is being actively exploited in the wild.
The following exploit code is available:
Solution / Fix
Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Various IP Security Camera ActiveX Controls 'url' Attribute Buffer Overflow Vulnerability
References:
References:
- 4xem VatCtrl Class Homepage (4xem)
- D-Link MPEG4 SHM Audio Control Homepage (D-Link)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vivotek RTSP MPEG4 SP Control Homepage (Vivotek)