Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
BID:28662
Info
Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 28662 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1724 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Patrick Webster |
| Vulnerable: |
Tumbleweed SecureTransport 4.6.1 |
| Not Vulnerable: | |
Discussion
Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Tumbleweed SecureTransport is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Tumbleweed SecureTransport is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
The following proof of concept is available:
An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious HTML page.
The following proof of concept is available:
Solution / Fix
Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
The vendor released SecureTransport 4.6.1 hotfix 20 to address this issue. Please see the references for more information.
Solution:
The vendor released SecureTransport 4.6.1 hotfix 20 to address this issue. Please see the references for more information.
References
Tumbleweed SecureTransport 'vcst_eu.dll' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- SecureTransport Homepage (Tumbleweed)
- Tumbleweed SecureTransport FileTransfer ActiveX Control Buffer Overflow ('Patrick Webster'
)