Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
BID:29391
Info
Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 29391 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0955 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2008 12:00AM |
| Updated: | Jun 10 2008 11:12PM |
| Credit: | Greg Linares of eEye Digital Security |
| Vulnerable: |
Creative Labs Creative Software AutoUpdate 0 |
| Not Vulnerable: | |
Discussion
Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
Creative Software AutoUpdate Engine is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Creative Software AutoUpdate Engine is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of an application using the ActiveX control (typically Internet Explorer). Failed attacks will likely cause denial-of-service conditions.
Exploit / POC
Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
UPDATE: Symantec has seen evidence that this issue is being actively exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
UPDATE: Symantec has seen evidence that this issue is being actively exploited in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploit is available:
Solution / Fix
Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Creative Labs AutoUpdate Eng 'CTSUEng.ocx' ActiveX Control Remote Buffer Overflow Vulnerability
References:
References:
- Vendor Homepage (Creative Labs)
- Vulnerability Note VU#501843 Creative Software AutoUpdate Engine stack buffer (US-CERT)