Interwoven WorkSite Web 'iManFile.cab' TransferCtrl Class ActiveX Control Double Free Vulnerability
BID:28628
Info
Interwoven WorkSite Web 'iManFile.cab' TransferCtrl Class ActiveX Control Double Free Vulnerability
| Bugtraq ID: | 28628 |
| Class: | Design Error |
| CVE: |
CVE-2008-1617 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 04 2008 12:00AM |
| Updated: | Apr 16 2015 06:02PM |
| Credit: | MWR InfoSecurity |
| Vulnerable: |
Interwoven Inc. WorkSite 8.2 |
| Not Vulnerable: |
Interwoven Inc. WorkSite Web 8.2 SP1 P2 |
Discussion
Interwoven WorkSite Web 'iManFile.cab' TransferCtrl Class ActiveX Control Double Free Vulnerability
Interwoven WorkSite Web TransferCtrl Class ActiveX control is prone a double-free vulnerability because of a flaw in the way that it uses a certain JavaScript variable.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to WorkSite Web 8.2 SP1 P2 are vulnerable.
Interwoven WorkSite Web TransferCtrl Class ActiveX control is prone a double-free vulnerability because of a flaw in the way that it uses a certain JavaScript variable.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to WorkSite Web 8.2 SP1 P2 are vulnerable.
Exploit / POC
Interwoven WorkSite Web 'iManFile.cab' TransferCtrl Class ActiveX Control Double Free Vulnerability
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious web document.
The following proof-of-concept code is available:
To exploit this issue, an attacker must entice an unsuspecting user to open a malicious web document.
The following proof-of-concept code is available:
Solution / Fix
References
Interwoven WorkSite Web 'iManFile.cab' TransferCtrl Class ActiveX Control Double Free Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (Interwoven, Inc.)
- WorkSite Support Page (Interwoven, Inc.)
- Interwoven Worksite ?- ActiveX Control Remote Code Execution (MWR InfoSecurity)