LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
BID:28442
Info
LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
| Bugtraq ID: | 28442 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1605 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 25 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | shinnai |
| Vulnerable: |
LeadTools Multimedia 15 |
| Not Vulnerable: | |
Discussion
LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
LEADTOOLS Multimedia is prone to multiple vulnerabilities that allow attackers to overwrite arbitrary files. These issues affect multiple ActiveX controls.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
LEADTOOLS Multimedia 15 is vulnerable; other versions may also be affected.
LEADTOOLS Multimedia is prone to multiple vulnerabilities that allow attackers to overwrite arbitrary files. These issues affect multiple ActiveX controls.
An attacker can exploit these issues by enticing an unsuspecting victim to view a malicious HTML page.
Successfully exploiting these issues will allow the attacker to corrupt and overwrite arbitrary files on the victim's computer in the context of the vulnerable application using the ActiveX control (typically Internet Explorer).
LEADTOOLS Multimedia 15 is vulnerable; other versions may also be affected.
Exploit / POC
LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example exploit is available:
An attacker can exploit these issues by enticing an unsuspecting victim to follow a malicious URI.
The following example exploit is available:
Solution / Fix
LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
LEADTOOLS Multimedia 'LTMM15.DLL' ActiveX Control Arbitrary File Overwrite Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (LEADTOOLS)