NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
BID:29395
Info
NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 29395 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0958 |
| Remote: | Yes |
| Local: | No |
| Published: | May 27 2008 12:00AM |
| Updated: | May 27 2008 12:00AM |
| Credit: | Will Dormann of CERT/CC |
| Vulnerable: |
Sagasoft Saga CD Ripper 1 Online Media Technologies NCTSoft NCTAudioGrabber2 0 Magic Software Magic Rm AVI Mpeg to MP3 Converter & Editor 2 Code-it Software Wave MP3 Editor 15 Code-it Software Wave MP3 Editor 10 Code-it Software aBasic Editor 10.1 Code-it Software aBasic Editor 10 Audiotool.net Ease MP3 Recorder 1 Audiotool.net Ease Jukebox 1 |
| Not Vulnerable: | |
Discussion
NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
The NCTSoft NCTAudioGrabber2 ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
The NCTSoft NCTAudioGrabber2 ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
An attacker can exploit this issue by enticing an unsuspecting to victim to visit a malicious web page.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
An attacker can exploit this issue by enticing an unsuspecting to victim to visit a malicious web page.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
NCTSoft NCTAudioGrabber2 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities
References:
References:
- Audiotool.net Homepage (Audiotool.net)
- Magic Software Homepage (Magic Software)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Sagasoft Homepage (Sagasoft)
- Vendor Homepage (Online Media Technologies )
- Vendor Homepage (MightSOFT)
- Vulnerability Note VU#656593 (US-CERT)