BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
BID:28292
Info
BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 28292 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-6254 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 18 2008 12:00AM |
| Updated: | Mar 19 2008 03:10PM |
| Credit: | Will Dormann of the CERT/CC is credited with discovering this vulnerability. |
| Vulnerable: |
Business Objects BusinessObjects 6.5 |
| Not Vulnerable: | |
Discussion
BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
BusinessObjects 'RptViewerAX' is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of an application using the affected control (typically Internet Explorer). Successful attacks can compromise the application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
BusinessObjects 'RptViewerAX' is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code in the context of an application using the affected control (typically Internet Explorer). Successful attacks can compromise the application and possibly the underlying computer. Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
Solution:
The vendor released hotfix CHF74 to address this issue. Please see the references for information on how to obtain and apply this fix.
Solution:
The vendor released hotfix CHF74 to address this issue. Please see the references for information on how to obtain and apply this fix.
References
BusinessObjects 'RptViewerAX' ActiveX Control Stack Based Buffer Overflow Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Service Packs Page (Business Objects)
- Vendor Homepage (Business Objects)
- Vulnerability Note VU#329673 BusinessObjects RptViewerAX ActiveX control stack (US-CERT)