Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
BID:28287
Info
Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
| Bugtraq ID: | 28287 |
| Class: | Unknown |
| CVE: |
CVE-2008-7122 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2008 12:00AM |
| Updated: | Apr 16 2015 06:05PM |
| Credit: | t0pP8uZz discovered these issues. |
| Vulnerable: |
Evans Programming Registry Pro - ActiveX Registry Control 0 |
| Not Vulnerable: | |
Discussion
Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
Registry Pro 'epRegPro.ocx' ActiveX control is prone to multiple vulnerabilities, including an insecure-method issue and a buffer-overflow issue.
An attacker can exploit these issues to delete arbitrary registry keys and to execute arbitrary code in the context of an application running the control (typically Internet Explorer). Failed attacks will cause denial-of-service conditions.
NOTE: Further analysis indicates that the trial version of Registry Pro 2.2.7 is not marked 'safe for scripting', which makes it not vulnerable; versions installed with other installers may be marked safe. We will update this BID as more information emerges.
Registry Pro 'epRegPro.ocx' ActiveX control is prone to multiple vulnerabilities, including an insecure-method issue and a buffer-overflow issue.
An attacker can exploit these issues to delete arbitrary registry keys and to execute arbitrary code in the context of an application running the control (typically Internet Explorer). Failed attacks will cause denial-of-service conditions.
NOTE: Further analysis indicates that the trial version of Registry Pro 2.2.7 is not marked 'safe for scripting', which makes it not vulnerable; versions installed with other installers may be marked safe. We will update this BID as more information emerges.
Exploit / POC
Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting user to visit a malicious webpage.
The following exploit code is available:
To exploit these issues, an attacker must entice an unsuspecting user to visit a malicious webpage.
The following exploit code is available:
Solution / Fix
Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Registry Pro 'epRegPro.ocx' ActiveX Control Insecure Method And Buffer Overflow Vulnerabilities
References:
References:
- Registry Pro - ActiveX Registry Control (Evans Programming)