PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
BID:29279
Info
PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 29279 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0957 |
| Remote: | Yes |
| Local: | No |
| Published: | May 19 2008 12:00AM |
| Updated: | Nov 03 2008 03:35PM |
| Credit: | Will Dormann of the CERT/CC |
| Vulnerable: |
PhotoStockPlus.com PSPUploader.ocx 0 |
| Not Vulnerable: | |
Discussion
PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
An ActiveX control in the image uploader tool of StockPhotoPlus is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
These issues occur in 'PSPUploader.ocx' which is shipped with PhotoStockPlus Uploader Tool version 1.0.
An ActiveX control in the image uploader tool of StockPhotoPlus is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
These issues occur in 'PSPUploader.ocx' which is shipped with PhotoStockPlus Uploader Tool version 1.0.
Exploit / POC
PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
Solution:
The vendor released an advisory and fixes to address these issues. Please see the references for more information.
NOTE: Microsoft released a security advisory (956391) and updates that fix the issues by setting the kill bit on the affected control.
UPDATE (October 29, 2008): Users with Microsoft SQL Server 2005 Reporting Services Add-in for Microsoft SharePoint Technologies who have installed this update will not be able to print until they upgrade to the latest version. See the Microsoft Security Advisory 956391 for details.
Solution:
The vendor released an advisory and fixes to address these issues. Please see the references for more information.
NOTE: Microsoft released a security advisory (956391) and updates that fix the issues by setting the kill bit on the affected control.
UPDATE (October 29, 2008): Users with Microsoft SQL Server 2005 Reporting Services Add-in for Microsoft SharePoint Technologies who have installed this update will not be able to print until they upgrade to the latest version. See the Microsoft Security Advisory 956391 for details.
References
PhotoStockPlus Uploader Tool ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vendor Homepage (PhotoStockPlus.com)
- ActiveX Photostock Uploader Tool Discontinued (PhotoStockPlus)
- Microsoft Security Advisory (956391) - Cumulative Security Update of ActiveX Kil (Microsoft)
- Vulnerability Note VU#406937 PhotoStockPlus Uploader Tool ActiveX stack buffer o (US-CERT)